Ensemble-based Blackbox Attacks on Dense Prediction

被引:12
作者
Cai, Zikui [1 ]
Tan, Yaoteng [1 ]
Asif, M. Salman [1 ]
机构
[1] Univ Calif Riverside, Riverside, CA 92521 USA
来源
2023 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION, CVPR | 2023年
关键词
D O I
10.1109/CVPR52729.2023.00394
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
We propose an approach for adversarial attacks on dense prediction models (such as object detectors and segmentation). It is well known that the attacks generated by a single surrogate model do not transfer to arbitrary (blackbox) victim models. Furthermore, targeted attacks are often more challenging than the untargeted attacks. In this paper, we show that a carefully designed ensemble can create effective attacks for a number of victim models. In particular, we show that normalization of the weights for individual models plays a critical role in the success of the attacks. We then demonstrate that by adjusting the weights of the ensemble according to the victim model can further improve the performance of the attacks. We performed a number of experiments for object detectors and segmentation to highlight the significance of the our proposed methods. Our proposed ensemble-based method outperforms existing blackbox attack methods for object detection and segmentation. Finally we show that our proposed method can also generate a single perturbation that can fool multiple blackbox detection and segmentation models simultaneously. Code is available at https://github.com/CSIPlab/EBAD.
引用
收藏
页码:4045 / 4055
页数:11
相关论文
共 62 条
[51]  
Wei XX, 2019, PROCEEDINGS OF THE TWENTY-EIGHTH INTERNATIONAL JOINT CONFERENCE ON ARTIFICIAL INTELLIGENCE, P954
[52]   Ground Simulation Test of 2D Dynamic Overload Environment of Fuze Launching [J].
Wu, Zhibo ;
Ma, Tiehua ;
Zhang, Yanbing ;
Zhang, Hongyan .
SHOCK AND VIBRATION, 2020, 2020
[53]   Unified Perceptual Parsing for Scene Understanding [J].
Xiao, Tete ;
Liu, Yingcheng ;
Zhou, Bolei ;
Jiang, Yuning ;
Sun, Jian .
COMPUTER VISION - ECCV 2018, PT V, 2018, 11209 :432-448
[54]   Improving Transferability of Adversarial Examples with Input Diversity [J].
Xie, Cihang ;
Zhang, Zhishuai ;
Zhou, Yuyin ;
Bai, Song ;
Wang, Jianyu ;
Ren, Zhou ;
Yuille, Alan .
2019 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR 2019), 2019, :2725-2734
[55]   Adversarial Examples for Semantic Segmentation and Object Detection [J].
Xie, Cihang ;
Wang, Jianyu ;
Zhang, Zhishuai ;
Zhou, Yuyin ;
Xie, Lingxi ;
Yuille, Alan .
2017 IEEE INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV), 2017, :1378-1387
[56]  
Yuan Z., 2021, P IEEE CVF INT C COM, P7748
[57]   Context Encoding for Semantic Segmentation [J].
Zhang, Hang ;
Dana, Kristin ;
Shi, Jianping ;
Zhang, Zhongyue ;
Wang, Xiaogang ;
Tyagi, Ambrish ;
Agrawal, Amit .
2018 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2018, :7151-7160
[58]   Bridging the Gap Between Anchor-based and Anchor-free Detection via Adaptive Training Sample Selection [J].
Zhang, Shifeng ;
Chi, Cheng ;
Yao, Yongqiang ;
Lei, Zhen ;
Li, Stan Z. .
2020 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR 2020), 2020, :9756-9765
[59]  
Zhang XS, 2019, ADV NEUR IN, V32
[60]   PSANet: Point-wise Spatial Attention Network for Scene Parsing [J].
Zhao, Hengshuang ;
Zhang, Yi ;
Liu, Shu ;
Shi, Jianping ;
Loy, Chen Change ;
Lin, Dahua ;
Jia, Jiaya .
COMPUTER VISION - ECCV 2018, PT IX, 2018, 11213 :270-286