Zero-Shot Attribute Attacks on Fine-Grained Recognition Models

被引:1
|
作者
Shafiee, Nasim [1 ]
Elhamifar, Ehsan [1 ]
机构
[1] Northeastern Univ, Boston, MA 02115 USA
来源
关键词
Fine-grained recognition; Zero-shot models; Adversarial attacks; Attribute-based universal perturbations; Compositional model;
D O I
10.1007/978-3-031-20065-6_16
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Zero-shot fine-grained recognition is an important classification task, whose goal is to recognize visually very similar classes, including the ones without training images. Despite recent advances on the development of zero-shot fine-grained recognition methods, the robustness of such models to adversarial attacks is not well understood. On the other hand, adversarial attacks have been widely studied for conventional classification with visually distinct classes. Such attacks, in particular, universal perturbations that are class-agnostic and ideally should generalize to unseen classes, however, cannot leverage or capture small distinctions among fine-grained classes. Therefore, we propose a compositional attribute-based framework for generating adversarial attacks on zero-shot fine-grained recognition models. To generate attacks that capture small differences between fine-grained classes, generalize well to previously unseen classes and can be applied in real-time, we propose to learn and compose multiple attribute-based universal perturbations (AUPs). Each AUP corresponds to an image-agnostic perturbation on a specific attribute. To build our attack, we compose AUPs with weights obtained by learning a class-attribute compatibility function. To learn the AUPs and the parameters of our model, we minimize a loss, consisting of a ranking loss and a novel utility loss, which ensures AUPs are effectively learned and utilized. By extensive experiments on three datasets for zero-shot fine-grained recognition, we show that our attacks outperform conventional universal classification attacks and transfer well between different recognition architectures.
引用
收藏
页码:262 / 282
页数:21
相关论文
共 50 条
  • [21] Correction to: Zero-shot Fine-grained Classification by Deep Feature Learning with Semantics
    Ao-Xue Li
    Ke-Xin Zhang
    Li-Wei Wang
    International Journal of Automation and Computing, 2021, 18 : 1045 - 1045
  • [22] Zero-shot fine-grained entity typing in information security based on ontology
    Zhang, Han
    Zhu, Jiaxian
    Chen, Jicheng
    Liu, Junxiu
    Ji, Lixia
    KNOWLEDGE-BASED SYSTEMS, 2021, 232
  • [23] Integrate d generalize d zero-shot learning for fine-grained classification
    Shermin, Tasfia
    Teng, Shyh Wei
    Sohel, Ferdous
    Murshed, Manzur
    Lu, Guojun
    PATTERN RECOGNITION, 2022, 122
  • [24] CASE 2021 Task 2: Zero-Shot Classification of Fine-Grained Sociopolitical Events with Transformer Models
    Radford, Benjamin J.
    CASE 2021: THE 4TH WORKSHOP ON CHALLENGES AND APPLICATIONS OF AUTOMATED EXTRACTION OF SOCIO-POLITICAL EVENTS FROM TEXT (CASE), 2021, : 203 - 207
  • [25] Fine-grained Textual Inversion Network for Zero-Shot Composed Image Retrieval
    Lin, Haoqiang
    Wen, Haokun
    Song, Xuemeng
    Liu, Meng
    Hu, Yupeng
    Nie, Liqiang
    PROCEEDINGS OF THE 47TH INTERNATIONAL ACM SIGIR CONFERENCE ON RESEARCH AND DEVELOPMENT IN INFORMATION RETRIEVAL, SIGIR 2024, 2024, : 240 - 250
  • [26] An Attribute Learning Method for Zero-Shot Recognition
    Yazdanian, Ramtin
    Shojaee, Seyed Mohsen
    Baghshah, Mahdieh Soleymani
    2017 25TH IRANIAN CONFERENCE ON ELECTRICAL ENGINEERING (ICEE), 2017, : 2235 - 2240
  • [27] An Empirical Study on Multiple Information Sources for Zero-Shot Fine-Grained Entity Typing
    Chen, Yi
    Jiang, Haiyun
    Liu, Lemao
    Shi, Shuming
    Fan, Chuang
    Yang, Min
    Xu, Ruifeng
    2021 CONFERENCE ON EMPIRICAL METHODS IN NATURAL LANGUAGE PROCESSING (EMNLP 2021), 2021, : 2668 - 2678
  • [28] UniFine: A Unified and Fine-grained Approach for Zero-shot Vision-Language Understanding
    Sun, Rui
    Wang, Zhecan
    You, Haoxuan
    Codella, Noel
    Chang, Kai-Wei
    Chang, Shih-Fu
    FINDINGS OF THE ASSOCIATION FOR COMPUTATIONAL LINGUISTICS, ACL 2023, 2023, : 778 - 793
  • [29] Stacked Semantics-Guided Attention Model for Fine-Grained Zero-Shot Learning
    Yu, Yunlong
    Ji, Zhong
    Fu, Yanwei
    Guo, Jichang
    Pang, Yanwei
    Zhang, Zhongfei
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 31 (NIPS 2018), 2018, 31
  • [30] Content-Aware Rectified Activation for Zero-Shot Fine-Grained Image Retrieval
    Wang, Shijie
    Chang, Jianlong
    Wang, Zhihui
    Li, Haojie
    Ouyang, Wanli
    Tian, Qi
    IEEE TRANSACTIONS ON PATTERN ANALYSIS AND MACHINE INTELLIGENCE, 2024, 46 (06) : 4366 - 4380