Prevention from Automated Analysis Services with Object-Level Adversarial Examples
Prevention from Automated Analysis Services with Object-Level Adversarial Examples
批准号:
21K18023
负责人:
レ チュンギア
金额:
$2.91万
依托单位国家:
日本
项目类别:
Grant-in-Aid for Early-Career Scientists
财政年份:
2021
资助国家:
日本
项目状态:
已结题
起止时间:
2021-04-01 至 2023-03-31
中文摘要
我们提出了两个基于对抗性例子的保护系统。在第一个系统中,我们通过自动识别可保护区域以最小化对图像质量的影响以及合成不明显和自然的对抗性纹理来保护人们免受人类实例分割网络的影响。该系统已在2021年CVPR研讨会上发布。在第二个系统中,我们保护位置隐私不受地标识别系统的影响。特别是,我们引入了掩模引导的多峰投影梯度下降(MM-PGD)算法,以提高对各种深度模型的保护。我们还研究了不同的可保护区域识别策略来防御黑盒地标识别系统,而不需要太多的图像处理。这项工作被WIFS2022接受,我们还分析了对抗性范例的类别意识转移,以表明对抗性范例的非目标转移与相同错误之间的密切联系。通过扩展Ilyas等人的框架,我们证明了非稳健特征可以全面地解释不同错误和相同错误之间的差异。特别地,我们证明了当对抗性例子中被操纵的非稳健特征被多个模型不同地使用时,这些模型可能会对对抗性例子进行不同的分类。这项工作被WACV 2023接受。
英文摘要
We proposed two protection systems based on adversarial examples. In the first system, we protect people from human instance segmentation networks by automatically identifying protectable regions to minimize the effect on image quality and synthesizing inconspicuous and natural adversarial textures. This system was published at CVPR Workshops 2021. In the second system, we protect location privacy against landmark recognition systems. In particular, we introduce mask-guided multimodal projected gradient descent (MM-PGD) to improve the protection against various deep models. We also investigated different protectable region identification strategies to defend against black-box landmark recognition systems without the need for much image manipulation. This work was accepted to WIFS 2022.We also analyzed class-aware transferability of adversarial examples to show the strong connection between non-targeted transferability of adversarial examples and same mistakes. We demonstrated that non-robust features can comprehensively explain the difference between a different mistake and a same mistake by extending the framework of Ilyas et al. In particular, we showed that when the manipulated nonrobust features in an adversarial examples are differently used by multiple models, those models may classify the adversarial examples differently. This work was accepted to WACV 2023.
期刊论文(10)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
DOI:
10.1109/iccv48922.2021.00996
发表时间:
2021-07
期刊:
2021 IEEE/CVF International Conference on Computer Vision (ICCV)
影响因子:
--
作者:
[Trung-Nghia Le;H. Nguyen;J. Yamagishi;I. Echizen]
通讯作者:
Trung-Nghia Le;H. Nguyen;J. Yamagishi;I. Echizen
DOI:
10.1109/wacv56688.2023.00194
发表时间:
2022-10
期刊:
2023 IEEE/CVF Winter Conference on Applications of Computer Vision (WACV)
影响因子:
--
作者:
[H. Nguyen;Trung-Nghia Le;J. Yamagishi;I. Echizen]
通讯作者:
H. Nguyen;Trung-Nghia Le;J. Yamagishi;I. Echizen
Fashion-Guided Adversarial Attack on Person Segmentation
时尚引导的人体分割对抗性攻击
DOI:
--
发表时间:
2021
期刊:
影响因子:
--
作者:
[Marc Treu, Trung-Nghia Le, Huy H. Nguyen, Junichi Yamagishi, Isao Echizen]
通讯作者:
Isao Echizen
DOI:
10.1109/wacv56688.2023.00141
发表时间:
2021-12
期刊:
2023 IEEE/CVF Winter Conference on Applications of Computer Vision (WACV)
影响因子:
--
作者:
[Futa Waseda;Sosuke Nishikawa;Trung-Nghia Le;H. Nguyen;I. Echizen]
通讯作者:
Futa Waseda;Sosuke Nishikawa;Trung-Nghia Le;H. Nguyen;I. Echizen
Rethinking Adversarial Examples for Location Privacy Protection
重新思考位置隐私保护的对抗性例子
DOI:
--
发表时间:
2022
期刊:
影响因子:
--
作者:
[Trung-Nghia Le, Ta Gu, Huy H. Nguyen, Isao Echizen]
通讯作者:
Isao Echizen
共 10 条
海外基金