REAP: A Large-Scale Realistic Adversarial Patch Benchmark

被引:2
|
作者
Hingun, Nabeel [1 ]
Sitawarin, Chawin [1 ]
Li, Jerry [2 ]
Wagner, David [1 ]
机构
[1] Univ Calif Berkeley, Berkeley, CA 94720 USA
[2] Microsoft, Redmond, WA USA
关键词
D O I
10.1109/ICCV51070.2023.00428
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Machine learning models are known to be susceptible to adversarial perturbation. One famous attack is the adversarial patch, a particularly crafted sticker that makes the model mispredict the object it is placed on. This attack presents a critical threat to cyber-physical systems that rely on cameras such as autonomous cars. Despite the significance of the problem, conducting research in this setting has been difficult; evaluating attacks and defenses in the real world is exceptionally costly while synthetic data are unrealistic. In this work, we propose the REAP (REalistic Adversarial Patch) benchmark, a digital benchmark that enables the evaluations on real images under real-world conditions. Built on top of the Mapillary Vistas dataset, our benchmark contains over 14,000 traffic signs. Each sign is augmented with geometric and lighting transformations for applying a digitally generated patch realistically onto the sign. Using our benchmark, we perform the first large-scale assessments of adversarial patch attacks under realistic conditions. Our experiments suggest that patch attacks may present a smaller threat than previously believed and that the success rate of an attack on simpler digital simulations is not predictive of its actual effectiveness in practice. Our benchmark is released publicly at https://github.com/wagner-group/reap-benchmark.
引用
收藏
页码:4617 / 4628
页数:12
相关论文
共 50 条
  • [1] A Large-Scale Homography Benchmark
    Barath, Daniel
    Mishkin, Dmytro
    Polic, Michal
    Forstner, Wolfgang
    Matas, Jiri
    [J]. 2023 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2023, : 21360 - 21370
  • [2] OmniArt: A Large-scale Artistic Benchmark
    Strezoski, Gjorgji
    Worring, Marcel
    [J]. ACM TRANSACTIONS ON MULTIMEDIA COMPUTING COMMUNICATIONS AND APPLICATIONS, 2018, 14 (04)
  • [3] Large-Scale Patch Recommendation at Alibaba
    Zhang, Xindong
    Zhu, Chenguang
    Li, Yi
    Guo, Jianmei
    Liu, Lihua
    Gu, Haobo
    [J]. 2020 ACM/IEEE 42ND INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING: COMPANION PROCEEDINGS (ICSE-COMPANION 2020), 2020, : 252 - 253
  • [4] A large-scale benchmark of gene prioritization methods
    Dimitri Guala
    Erik L. L. Sonnhammer
    [J]. Scientific Reports, 7
  • [5] A large-scale benchmark of gene prioritization methods
    Guala, Dimitri
    Sonnhammer, Erik L. L.
    [J]. SCIENTIFIC REPORTS, 2017, 7
  • [6] A Large-Scale Benchmark for Food Image Segmentation
    Wu, Xiongwei
    Fu, Xin
    Liu, Ying
    Lim, Ee-Peng
    Hoi, Steven C. H.
    Sun, Qianru
    [J]. PROCEEDINGS OF THE 29TH ACM INTERNATIONAL CONFERENCE ON MULTIMEDIA, MM 2021, 2021, : 506 - 515
  • [7] The Steganographer is the Outlier: Realistic Large-Scale Steganalysis
    Ker, Andrew D.
    Pevny, Tomas
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2014, 9 (09) : 1424 - 1435
  • [8] Realistic large-scale online network simulation
    Liu, X.
    Chien, A. A.
    [J]. INTERNATIONAL JOURNAL OF HIGH PERFORMANCE COMPUTING APPLICATIONS, 2006, 20 (03): : 383 - 399
  • [9] The Seelabor Realistic Large-Scale Trials in the Field
    不详
    [J]. HYDROLOGIE UND WASSERBEWIRTSCHAFTUNG, 2012, 56 (02): : 91 - 91
  • [10] Adversarial Large-scale Root Gap Inpainting
    Chen, Hao
    Giuffrida, Mario Valerio
    Doerner, Peter
    Tsaftaris, Sotirios A.
    [J]. 2019 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION WORKSHOPS (CVPRW 2019), 2019, : 2619 - 2628