Ensemble-based Blackbox Attacks on Dense Prediction

Ensemble-based Blackbox Attacks on Dense Prediction
复制标题

DOI:
10.1109/cvpr52729.2023.00394
复制
发表时间:
2023-03
期刊:
2023 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR)
影响因子:
--
通讯作者:
Zikui Cai;Yaoteng Tan;M. Salman Asif
Zikui Cai;Yaoteng Tan;M. Salman Asif
中科院分区:
其他
文献类型:
--
作者:
Zikui Cai;Yaoteng Tan;M. Salman Asif

文献摘要

相似文献

我们提出了一种对密集预测模型(如对象检测器和分割)进行对抗性攻击的方法。众所周知,由单个代理模型产生的攻击不会转移到任意(黑盒)受害者模型。此外,有针对性的攻击往往比无针对性的攻击更具挑战性。在本文中,我们表明,一个精心设计的合奏可以创建有效的攻击的受害者模型。特别是,我们证明了各个模型的权重的归一化在攻击的成功中起着至关重要的作用。然后,我们证明,通过调整权重的合奏根据受害者模型可以进一步提高攻击的性能。我们对对象检测器和分割进行了许多实验,以强调我们提出的方法的重要性。我们提出的基于集合的方法优于现有的黑盒攻击方法的对象检测和分割。最后,我们表明,我们提出的方法也可以产生一个单一的扰动,可以欺骗多个黑盒检测和分割模型同时进行。代码可在https://github.com/CSIPlab/EBAD上获得
We propose an approach for adversarial attacks on dense prediction models (such as object detectors and segmentation). It is well known that the attacks generated by a single surrogate model do not transfer to arbitrary (blackbox) victim models. Furthermore, targeted attacks are often more challenging than the untargeted attacks. In this paper, we show that a carefully designed ensemble can create effective attacks for a number of victim models. In particular, we show that normalization of the weights for individual models plays a critical role in the success of the attacks. We then demonstrate that by adjusting the weights of the ensemble according to the victim model can further improve the performance of the attacks. We performed a number of experiments for object detectors and segmentation to highlight the significance of the our proposed methods. Our proposed ensemble-based method outperforms existing blackbox attack methods for object detection and segmentation. Finally we show that our proposed method can also generate a single perturbation that can fool multiple blackbox detection and segmentation models simultaneously. Code is available at https://github.com/CSIPlab/EBAD