Zero-Shot Attribute Attacks on Fine-Grained Recognition Models

被引:1
|
作者
Shafiee, Nasim [1 ]
Elhamifar, Ehsan [1 ]
机构
[1] Northeastern Univ, Boston, MA 02115 USA
来源
关键词
Fine-grained recognition; Zero-shot models; Adversarial attacks; Attribute-based universal perturbations; Compositional model;
D O I
10.1007/978-3-031-20065-6_16
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Zero-shot fine-grained recognition is an important classification task, whose goal is to recognize visually very similar classes, including the ones without training images. Despite recent advances on the development of zero-shot fine-grained recognition methods, the robustness of such models to adversarial attacks is not well understood. On the other hand, adversarial attacks have been widely studied for conventional classification with visually distinct classes. Such attacks, in particular, universal perturbations that are class-agnostic and ideally should generalize to unseen classes, however, cannot leverage or capture small distinctions among fine-grained classes. Therefore, we propose a compositional attribute-based framework for generating adversarial attacks on zero-shot fine-grained recognition models. To generate attacks that capture small differences between fine-grained classes, generalize well to previously unseen classes and can be applied in real-time, we propose to learn and compose multiple attribute-based universal perturbations (AUPs). Each AUP corresponds to an image-agnostic perturbation on a specific attribute. To build our attack, we compose AUPs with weights obtained by learning a class-attribute compatibility function. To learn the AUPs and the parameters of our model, we minimize a loss, consisting of a ranking loss and a novel utility loss, which ensures AUPs are effectively learned and utilized. By extensive experiments on three datasets for zero-shot fine-grained recognition, we show that our attacks outperform conventional universal classification attacks and transfer well between different recognition architectures.
引用
收藏
页码:262 / 282
页数:21
相关论文
共 50 条
  • [41] Attribute subspaces for zero-shot learning
    Zhou, Lei
    Liu, Yang
    Bai, Xiao
    Li, Na
    Yu, Xiaohan
    Zhou, Jun
    Hancock, Edwin R.
    PATTERN RECOGNITION, 2023, 144
  • [42] Zero-Shot Learning with Attribute Selection
    Guo, Yuchen
    Ding, Guiguang
    Han, Jungong
    Tang, Sheng
    THIRTY-SECOND AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE / THIRTIETH INNOVATIVE APPLICATIONS OF ARTIFICIAL INTELLIGENCE CONFERENCE / EIGHTH AAAI SYMPOSIUM ON EDUCATIONAL ADVANCES IN ARTIFICIAL INTELLIGENCE, 2018, : 6870 - 6877
  • [43] Zero-shot Learning With Fuzzy Attribute
    Liu, Chongwen
    Shang, Zhaowei
    Tang, Yuan Yan
    2017 3RD IEEE INTERNATIONAL CONFERENCE ON CYBERNETICS (CYBCONF), 2017, : 277 - 282
  • [44] Zero-shot Fine-grained Classification by Deep Feature Learning with Semantics (vol 16, pg 563, 2019)
    Li, Ao-Xue
    Zhang, Ke-Xin
    Wang, Li-Wei
    INTERNATIONAL JOURNAL OF AUTOMATION AND COMPUTING, 2021, 18 (06) : 1045 - 1045
  • [45] Deformable Part Descriptors for Fine-grained Recognition and Attribute Prediction
    Zhang, Ning
    Farrell, Ryan
    Iandola, Forrest
    Darrell, Trevor
    2013 IEEE INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV), 2013, : 729 - 736
  • [46] Audio Visual Attribute Discovery for Fine-Grained Object Recognition
    Zhang, Hua
    Cao, Xiaochun
    Wang, Rui
    THIRTY-SECOND AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE / THIRTIETH INNOVATIVE APPLICATIONS OF ARTIFICIAL INTELLIGENCE CONFERENCE / EIGHTH AAAI SYMPOSIUM ON EDUCATIONAL ADVANCES IN ARTIFICIAL INTELLIGENCE, 2018, : 7542 - 7549
  • [47] A few-shot fine-grained image recognition method
    Wang, Jianwei
    Chen, Deyun
    BULLETIN OF THE POLISH ACADEMY OF SCIENCES-TECHNICAL SCIENCES, 2023, 71 (01)
  • [48] Feature fine-tuning and attribute representation transformation for zero-shot learning
    Pang, Shanmin
    He, Xin
    Hao, Wenyu
    Long, Yang
    COMPUTER VISION AND IMAGE UNDERSTANDING, 2023, 236
  • [49] Mining Fine-Grained Image-Text Alignment for Zero-Shot Captioning via Text-Only Training
    Qiu, Longtian
    Ning, Shan
    He, Xuming
    THIRTY-EIGHTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, VOL 38 NO 5, 2024, : 4605 - 4613
  • [50] Content-Dependent Fine-Grained Speaker Embedding for Zero-Shot Speaker Adaptation in Text-to-Speech Synthesis
    Zhou, Yixuan
    Song, Changhe
    Li, Xiang
    Zhang, Luwen
    Wu, Zhiyong
    Bian, Yanyao
    Su, Dan
    Meng, Helen
    INTERSPEECH 2022, 2022, : 2573 - 2577