Signals Are All You Need: Detecting and Mitigating Digital and Real-World Adversarial Patches Using Signal-Based Features

被引:0
|
作者
Bunzel, Niklas [1 ]
Frick, Raphael Antonius [1 ]
Klause, Gerrit [1 ]
Schwarte, Aino [2 ]
Honermann, Jonas [2 ]
机构
[1] Fraunhofer SIT ATHENE, Darmstadt, Hesse, Germany
[2] Tech Univ Darmstadt, Darmstadt, Hesse, Germany
关键词
Adversarial Patches; Detector; Adversarial Machine Learning; DOUBLE JPEG COMPRESSION; ATTACK;
D O I
10.1145/3665451.3665530
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
In recent times, neural networks have found their way into various applications and processes, including image classification, object detection for self-driving cars, and face recognition systems used for biometric verification and surveillance. However, even the most advanced object detectors remain susceptible to adversarial patch attacks - small distortions that can be digitally inserted into images or physically placed in the real world. These attacks can cause detectors to miss actual objects, detect non-existent ones, or predict incorrect object classes. Given their high confidence, these adversarial attacks pose a significant threat to the trustworthiness of AI-enabled systems. In this paper, we propose a novel detection approach for digital and real-world adversarial patches based on the analyses of handcrafted features derived from signal processing. We developed two versions of the algorithm: one approach is using Error Level Analysis, while the other is taking advantage of Haralick's texture features. By applying a Chan-Vese-based segmentation, regions potentially encompassing the adversarial patches can be identified. Image inpainting techniques based on signal-processing and diffusion models can then be used to remove the patches so that the model can produce the correct prediction output. We evaluated our approaches on various types of adversarial patches, i.e., real-world, textured digital, and smooth digital adversarial patches, as well as on classifiers trying to solve a multitude of tasks. When evaluating images featuring digital adversarial patches, we based our experiments on a subset of ImageNet and ImageNet-patch data sets, as well as on a subset of LFW and meaningful adversarial stickers. Utilizing the Error Level Analysis technique, we achieved accuracies between 93% and 86%. Meanwhile, the texture analysis method yielded accuracies of 86% and 67%, respectively. When considering real-world scenarios, our analysis was expanded to include the APRICOT and MS COCO datasets. Here, the ELA-based approach achieved an accuracy of 80%. The GLCM-based approach demonstrated a slightly higher accuracy of 81%. This indicates that both methods have practical applicability, with the GLCM-based approach showing a slight edge in real-world dataset performance.
引用
收藏
页码:24 / 34
页数:11
相关论文
共 16 条
  • [1] Fake it till you break it: Evaluating the Performance of Synthetically-optimized Adversarial Patches Against Real-world Imagery
    Zarei, Mohammad
    Ward, Chris M.
    Harguess, Josh
    Aiken, Marshal
    GEOSPATIAL INFORMATICS XIII, 2023, 12525
  • [2] Toward real-world activity recognition: An SVM based system using fuzzy directional features
    1600, World Scientific and Engineering Academy and Society, Ag. Ioannou Theologou 17-23, Zographou, Athens, 15773, Greece (10):
  • [3] Displaying digital holograms of real-world objects on a mobile device using tilt-based interaction
    Lehtimaki, Taina M.
    Saaskilahti, Kirsti
    Kowiel, Marcin
    Naughton, Thomas J.
    2010 9TH EURO-AMERICAN WORKSHOP ON INFORMATION OPTICS, 2010,
  • [4] Using Reinforcement Learning to Control Traffic Signals in a Real-World Scenario: An Approach Based on Linear Function Approximation
    Alegre, Lucas N.
    Ziemke, Theresa
    Bazzan, Ana L. C.
    IEEE TRANSACTIONS ON INTELLIGENT TRANSPORTATION SYSTEMS, 2022, 23 (07) : 9126 - 9135
  • [5] Detecting window line using an improved stacked hourglass network based on new real-world building facade dataset
    Yang, Fan
    Zhang, Yiding
    Jiao, Donglai
    Xu, Ke
    Wang, Dajiang
    Wang, Xiangyuan
    OPEN GEOSCIENCES, 2023, 15 (01)
  • [6] Detecting Chemical Hazards in Foods Using Microfluidic Paper-Based Analytical Devices (PADs): The Real-World Application
    Hua, Marti Z.
    Li, Shenmiao
    Wang, Shuo
    Lu, Xiaonan
    MICROMACHINES, 2018, 9 (01):
  • [7] Flexible online adaptation of learning strategy using EEG-based reinforcement signals in real-world robotic applications
    Kim, Su Kyoung
    Kirchner, Elsa Andrea
    Kirchner, Frank
    2020 IEEE INTERNATIONAL CONFERENCE ON ROBOTICS AND AUTOMATION (ICRA), 2020, : 4885 - 4891
  • [8] Machine Learning Based Monitoring of the Pneumatic Actuators' Behavior Through Signal Processing Using Real-World Data Set
    Kovacs, Tibor
    Ko, Andrea
    FUTURE DATA AND SECURITY ENGINEERING (FDSE 2019), 2019, 11814 : 33 - 44
  • [9] Detecting Knowledge of Incidentally Acquired, Real-World Memories Using a P300-Based Concealed-Information Test
    Meixner, John B.
    Rosenfeld, J. Peter
    PSYCHOLOGICAL SCIENCE, 2014, 25 (11) : 1994 - 2005
  • [10] Traffic Signal Control for Large-Scale Urban Traffic Networks: Real-World Experiments Using Vision-Based Sensors
    Park, Jiho
    Liu, Tong
    Wang, Chieh
    Wang, Hong
    Wang, Qichao
    Jiang, Zhong-Ping
    2024 IEEE 18TH INTERNATIONAL CONFERENCE ON CONTROL & AUTOMATION, ICCA 2024, 2024, : 282 - 287