Noise is Inside Me! Generating Adversarial Perturbations with Noise Derived from Natural Filters

被引:14
作者
Agarwal, Akshay [1 ]
Vatsa, Mayank [2 ]
Singh, Richa [2 ]
Ratha, Nalini K. [3 ]
机构
[1] IIIT Delhi, Delhi, India
[2] IIT Jodhpur, Jodhpur, Rajasthan, India
[3] IBM TJ Watson Res Ctr, Seattle, WA USA
来源
2020 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION WORKSHOPS (CVPRW 2020) | 2020年
关键词
IMAGE QUALITY ASSESSMENT; IDENTIFICATION; WATERMARKING;
D O I
10.1109/CVPRW50498.2020.00395
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Deep learning solutions are vulnerable to adversarial perturbations and can lead a "frog" image to be misclassified as a "deer" or random pattern into "guitar". Adversarial attack generation algorithms generally utilize the knowledge of database and CNN model to craft the noise. In this research, we present a novel scheme termed as Camera Inspired Perturbations to generate adversarial noise. The proposed approach relies on the noise embedded in the image due to environmental factors or camera noise incorporated. We extract these noise patterns using image filtering algorithms and incorporate them into images to generate adversarial images. Unlike most of the existing algorithms that require learning of noise, the proposed adversarial noise can be applied in real-time. It is model-agnostic and can be utilized to fool multiple deep learning classifiers on various databases. The effectiveness of the proposed approach is evaluated on five different databases with five different convolutional neural networks such as ResNet-50, VGG-16, and VGG-Face. The proposed attack reduces the classification accuracy of every network, for instance, the performance of VGG-16 on the Tiny ImageNet database is reduced by more than 33%. The robustness of the proposed adversarial noise is also evaluated against different adversarial defense algorithms.
引用
收藏
页码:3354 / 3363
页数:10
相关论文
共 55 条
  • [1] Iris sensor identification in multi-camera environment
    Agarwal, Akshay
    Keshari, Rohit
    Wadhwa, Manya
    Vijh, Mansi
    Parmar, Chandani
    Singh, Richa
    Vatsa, Mayank
    [J]. INFORMATION FUSION, 2019, 45 : 333 - 345
  • [2] Agarwal A, 2016, INT C PATT RECOG, P3001, DOI 10.1109/ICPR.2016.7900094
  • [3] Improving Spatial Resolution Using Incoherent Subtraction of Receive Beams Having Different Apodizations
    Agarwal, Anil
    Reeg, Jonathan
    Podkowa, Anthony S.
    Oelze, Michael L.
    [J]. IEEE TRANSACTIONS ON ULTRASONICS FERROELECTRICS AND FREQUENCY CONTROL, 2019, 66 (01) : 5 - 17
  • [4] [Anonymous], 2019, ICLR, DOI DOI 10.1080/13548506.2018.1510131
  • [5] [Anonymous], 2018, IEEE BTAS
  • [6] Athalye A, 2018, PR MACH LEARN RES, V80
  • [7] Steganalysis using image quality metrics
    Avcibas, I
    Memon, N
    Sankur, B
    [J]. IEEE TRANSACTIONS ON IMAGE PROCESSING, 2003, 12 (02) : 221 - 229
  • [8] Biggio Battista, 2013, Machine Learning and Knowledge Discovery in Databases. European Conference, ECML PKDD 2013. Proceedings: LNCS 8190, P387, DOI 10.1007/978-3-642-40994-3_25
  • [9] Towards Evaluating the Robustness of Neural Networks
    Carlini, Nicholas
    Wagner, David
    [J]. 2017 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP), 2017, : 39 - 57
  • [10] Chen PY, 2018, AAAI CONF ARTIF INTE, P10