Adversarial Halftone QR Code

被引:0
作者
Kamnounsing, Palakorn [1 ]
Sumongkayothin, Karin [1 ]
Siritanawan, Prarinya [2 ]
Kotani, Kazunori [2 ]
机构
[1] Mahidol Univ, Fac Engn, Dept Comp Engn, Nakhon Pathom 73120, Thailand
[2] Japan Adv Inst Sci & Technol, Nomi, Ishikawa 9231211, Japan
来源
IEEE ACCESS | 2024年 / 12卷
关键词
QR codes; Artificial intelligence; Object detection; Codes; Visualization; Training; Adversarial machine learning; Image classification; Machine learning; Neural networks; Adversarial attacks; adversarial patch; artificial intelligent; halftone QR Code; image classification model; machine learning; neural network; QR code;
D O I
10.1109/ACCESS.2024.3405408
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Recent studies have shown that machine-learning models are vulnerable to adversarial attacks. Adversarial attacks are deliberate attempts to modify the input data of a machine learning model in a way that causes it to produce incorrect predictions. One of the well-established formats of adversarial attacks is the adversarial patch, which takes the form of a small movable patch embedded with visual patterns. The adversarial patch can alter the classification results simply by attaching the patch to the target image scenes. In the previous work, additional data in the form of a QR code was successfully embedded alongside the adversarial patch, namely an adversarial QR code. It contains a dual function: the first function is an adversarial patch to attack an image classification model, and the second function is a QR code capable of embedding information. However, the scanning performance of the previous works was insufficient to be used in practice. To address this issue, this research proposes an adversarial halftone QR code that improves the scanning performance and maintains the efficiency of QR code-based adversarial attacks. The adversarial halftone QR code approach proposes the use of high-quality visual QR codes under a half-tone scheme that is effectively machine-readable under various conditions. The experimental results show that the adversarial halftone QR code exhibits better overall scanning performance across different devices and modules while maintaining its attack performance compared to the adversarial QR code.
引用
收藏
页码:126729 / 126737
页数:9
相关论文
共 21 条
[1]  
Adhikari A, 2020, Arxiv, DOI arXiv:2008.13671
[2]   Inconspicuous Adversarial Patches for Fooling Image-Recognition Systems on Mobile Devices [J].
Bai, Tao ;
Luo, Jinqi ;
Zhao, Jun .
IEEE INTERNET OF THINGS JOURNAL, 2022, 9 (12) :9515-9524
[3]  
Brown TB, 2018, Arxiv, DOI arXiv:1712.09665
[4]   Surreptitious Adversarial Examples through Functioning QR Code [J].
Chindaudom, Aran ;
Siritanawan, Prarinya ;
Sumongkayothin, Karin ;
Kotani, Kazunori .
JOURNAL OF IMAGING, 2022, 8 (05)
[5]   AdversarialQR: An adversarial patch in QR code format [J].
Chindaudom, Aran ;
Siritanawan, Prarinya ;
Sumongkayothin, Karin ;
Kotani, Kazunori .
2020 JOINT 9TH INTERNATIONAL CONFERENCE ON INFORMATICS, ELECTRONICS & VISION (ICIEV) AND 2020 4TH INTERNATIONAL CONFERENCE ON IMAGING, VISION & PATTERN RECOGNITION (ICIVPR), 2020,
[6]   Halftone QR Codes [J].
Chu, Hung-Kuo ;
Chang, Chia-Sheng ;
Lee, Ruen-Rone ;
Mitra, Niloy J. .
ACM TRANSACTIONS ON GRAPHICS, 2013, 32 (06)
[7]   Boosting Adversarial Attacks with Momentum [J].
Dong, Yinpeng ;
Liao, Fangzhou ;
Pang, Tianyu ;
Su, Hang ;
Zhu, Jun ;
Hu, Xiaolin ;
Li, Jianguo .
2018 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2018, :9185-9193
[8]  
Howard AG, 2017, Arxiv, DOI arXiv:1704.04861
[9]  
Goodfellow IJ, 2015, Arxiv, DOI arXiv:1412.6572
[10]  
Kurakin A, 2017, Arxiv, DOI arXiv:1607.02533