Black-box Adversarial Attack against Visual Interpreters for Deep Neural Networks

被引:0
作者
Hirose, Yudai [1 ]
Ono, Satoshi [1 ]
机构
[1] Kagoshima Univ, Kagoshima, Japan
来源
2023 18TH INTERNATIONAL CONFERENCE ON MACHINE VISION AND APPLICATIONS, MVA | 2023年
关键词
D O I
10.23919/MVA57639.2023.10215758
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
With the rapid development of deep neural networks (DNNs), eXplainable AI, which provides a basis for prediction on inputs, has become increasingly important. In addition, DNNs have a vulnerability called an Adversarial Example (AE), which can cause incorrect output by applying special perturbations to inputs. Potential vulnerabilities can also exist in image interpreters such as GradCAM, necessitating their investigation, as these vulnerabilities could potentially result in misdiagnosis within medical imaging. Therefore, this study proposes a black-box adversarial attack method that misleads the image interpreter using Sep-CMA-ES. The proposed method deceptively shifts the focus area of the image interpreter to a different location from that of the original image while maintaining the same predictive labels.
引用
收藏
页数:6
相关论文
共 36 条
  • [1] Abdukhamidov E., 2022, INTERPRETATIONS CANN
  • [2] POSTER: Black-box and Target-specific Attack Against Interpretable Deep Learning Systems
    Abdukhamidov, Eldor
    Juraev, Firuz
    Abuhamad, Mohammed
    Abuhmed, Tamer
    [J]. ASIA CCS'22: PROCEEDINGS OF THE 2022 ACM ASIA CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2022, : 1216 - 1218
  • [3] AdvEdge: Optimizing Adversarial Perturbations Against Interpretable Deep Learning
    Abdukhamidov, Eldor
    Abuhamad, Mohammed
    Juraev, Firuz
    Chan-Tin, Eric
    AbuHmed, Tamer
    [J]. COMPUTATIONAL DATA AND SOCIAL NETWORKS, CSONET 2021, 2021, 13116 : 93 - 105
  • [4] GenAttack: Practical Black-box Attacks with Gradient-Free Optimization
    Alzantot, Moustafa
    Sharma, Yash
    Chakraborty, Supriyo
    Zhang, Huan
    Hsieh, Cho-Jui
    Srivastava, Mani B.
    [J]. PROCEEDINGS OF THE 2019 GENETIC AND EVOLUTIONARY COMPUTATION CONFERENCE (GECCO'19), 2019, : 1111 - 1119
  • [5] Grad-CAM plus plus : Generalized Gradient-based Visual Explanations for Deep Convolutional Networks
    Chattopadhay, Aditya
    Sarkar, Anirban
    Howlader, Prantik
    Balasubramanian, Vineeth N.
    [J]. 2018 IEEE WINTER CONFERENCE ON APPLICATIONS OF COMPUTER VISION (WACV 2018), 2018, : 839 - 847
  • [6] HopSkipJumpAttack: A Query-Efficient Decision-Based Attack
    Chen, Jianbo
    Jordan, Michael, I
    Wainwright, Martin J.
    [J]. 2020 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP 2020), 2020, : 1277 - 1294
  • [7] Chen P-Y, 2017, ACM WORKSH ART INT S, P15, DOI DOI 10.1145/3128572.3140448
  • [8] Cheng M., 2020, INT C LEARNING REPRE
  • [9] Cohn R., 2012, Spearman 's rank correlation coefficient
  • [10] Dombrowski A.-K, 2019, Explanations can be manipulated and geometry is to blame