Shape Matters: Deformable Patch Attack

被引:32
作者
Chen, Zhaoyu [1 ]
Li, Bo [2 ]
Wu, Shuang [2 ]
Xu, Jianghe [2 ]
Ding, Shouhong [2 ]
Zhang, Wenqiang [1 ,3 ]
机构
[1] Fudan Univ, Acad Engn & Technol, Shanghai, Peoples R China
[2] Tencent, Youtu Lab, Shenzhen, Peoples R China
[3] Yiwu Res Inst Fudan Univ, Yiwu, Peoples R China
来源
COMPUTER VISION - ECCV 2022, PT IV | 2022年 / 13664卷
基金
中国国家自然科学基金;
关键词
Adversarial example; Patch attack; Shape representation; MODEL;
D O I
10.1007/978-3-031-19772-7_31
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Though deep neural networks (DNNs) have demonstrated excellent performance in computer vision, they are susceptible and vulnerable to carefully crafted adversarial examples which can mislead DNNs to incorrect outputs. Patch attack is one of the most threatening forms, which has the potential to threaten the security of real-world systems. Previous work always assumes patches to have fixed shapes, such as circles or rectangles, and it does not consider the shape of patches as a factor in patch attacks. To explore this issue, we propose a novel Deformable Patch Representation (DPR) that can harness the geometric structure of triangles to support the differentiable mapping between contour modeling and masks. Moreover, we introduce a joint optimization algorithm, named Deformable Adversarial Patch (DAPatch), which allows simultaneous and efficient optimization of shape and texture to enhance attack performance. We show that even with a small area, a particular shape can improve attack performance. Therefore, DAPatch achieves state-of-the-art attack performance by deforming shapes on GTSRB and ILSVRC2012 across various network architectures, and the generated patches can be threatening in the real world.
引用
收藏
页码:529 / 548
页数:20
相关论文
共 67 条
[1]  
Athalye A, 2018, PR MACH LEARN RES, V80
[2]   Shape matching and object recognition using shape contexts [J].
Belongie, S ;
Malik, J ;
Puzicha, J .
IEEE TRANSACTIONS ON PATTERN ANALYSIS AND MACHINE INTELLIGENCE, 2002, 24 (04) :509-522
[3]  
Bo Li, 2021, ADVM '21: Proceedings of the 1st International Workshop on Adversarial Learning for Multimedia, P35, DOI 10.1145/3475724.3483606
[4]  
Brown TB, 2018, Arxiv, DOI arXiv:1712.09665
[5]  
Bruna J., 2014, INT C LEARN REPR
[6]  
Chen C., 2022, INT WORKSHOP TRUSTAB
[7]   Towards Practical Certifiable Patch Defense with Vision Transformer [J].
Chen, Zhaoyu ;
Li, Bo ;
Xu, Jianghe ;
Wu, Shuang ;
Ding, Shouhong ;
Zhang, Wenqiang .
2022 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR 2022), 2022, :15127-15137
[8]  
Chiang P., 2020, OPENREVIEWNET
[9]   Deformable Convolutional Networks [J].
Dai, Jifeng ;
Qi, Haozhi ;
Xiong, Yuwen ;
Li, Yi ;
Zhang, Guodong ;
Hu, Han ;
Wei, Yichen .
2017 IEEE INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV), 2017, :764-773
[10]  
Ding L, 2021, AAAI CONF ARTIF INTE, V35, P1236