Is Deep Learning Safe for Robot Vision? Adversarial Examples against the iCub Humanoid

被引:44
作者
Melis, Marco [1 ]
Demontis, Ambra [1 ]
Biggio, Battista [1 ,2 ]
Brown, Gavin [3 ]
Fumera, Giorgio [1 ]
Roli, Fabio [1 ,2 ]
机构
[1] Univ Cagliari, Dept Elect & Elect Engn, Cagliari, Italy
[2] Pluribus One, Cagliari, Italy
[3] Univ Manchester, Sch Comp Sci, Manchester, Lancs, England
来源
2017 IEEE INTERNATIONAL CONFERENCE ON COMPUTER VISION WORKSHOPS (ICCVW 2017) | 2017年
关键词
SECURITY;
D O I
10.1109/ICCVW.2017.94
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Deep neural networks have been widely adopted in recent years, exhibiting impressive performances in several application domains. It has however been shown that they can be fooled by adversarial examples, i.e., images altered by a barely-perceivable adversarial noise, carefully crafted to mislead classification. In this work, we aim to evaluate the extent to which robot-vision systems embodying deep-learning algorithms are vulnerable to adversarial examples, and propose a computationally efficient countermeasure to mitigate this threat, based on rejecting classification of anomalous inputs. We then provide a clearer understanding of the safety properties of deep networks through an intuitive empirical analysis, showing that the mapping learned by such networks essentially violates the smoothness assumption of learning algorithms. We finally discuss the main limitations of this work, including the creation of real-world adversarial examples, and sketch promising research directions.
引用
收藏
页码:751 / 759
页数:9
相关论文
共 31 条
[11]   INTELLIGENCE REINVENTED [J].
Cristianini, Nello .
NEW SCIENTIST, 2016, 232 (3097) :37-41
[12]   On Security and Sparsity of Linear Classifiers for Adversarial Settings [J].
Demontis, Ambra ;
Russu, Paolo ;
Biggio, Battista ;
Fumera, Giorgio ;
Roli, Fabio .
STRUCTURAL, SYNTACTIC, AND STATISTICAL PATTERN RECOGNITION, S+SSPR 2016, 2016, 10029 :322-332
[13]  
Feinman Reuben, 2017, ARXIV170300410
[14]  
Goodfellow Ian J, 2015, INT C LEARN REPR ICL
[15]   Deep Neural Networks for Acoustic Modeling in Speech Recognition [J].
Hinton, Geoffrey ;
Deng, Li ;
Yu, Dong ;
Dahl, George E. ;
Mohamed, Abdel-rahman ;
Jaitly, Navdeep ;
Senior, Andrew ;
Vanhoucke, Vincent ;
Patrick Nguyen ;
Sainath, Tara N. ;
Kingsbury, Brian .
IEEE SIGNAL PROCESSING MAGAZINE, 2012, 29 (06) :82-97
[16]  
Huang L, 2011, P 4 ACM WORKSH SEC A, P43, DOI DOI 10.1145/2046684.2046692
[17]   ImageNet Classification with Deep Convolutional Neural Networks [J].
Krizhevsky, Alex ;
Sutskever, Ilya ;
Hinton, Geoffrey E. .
COMMUNICATIONS OF THE ACM, 2017, 60 (06) :84-90
[18]  
Kurakin A., 2016, ARXIV
[19]  
Li Xin, 2016, ABS161207767 CORR
[20]  
Mahendran A, 2015, PROC CVPR IEEE, P5188, DOI 10.1109/CVPR.2015.7299155