REAP: A Large-Scale Realistic Adversarial Patch Benchmark

被引:2
|
作者
Hingun, Nabeel [1 ]
Sitawarin, Chawin [1 ]
Li, Jerry [2 ]
Wagner, David [1 ]
机构
[1] Univ Calif Berkeley, Berkeley, CA 94720 USA
[2] Microsoft, Redmond, WA USA
关键词
D O I
10.1109/ICCV51070.2023.00428
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Machine learning models are known to be susceptible to adversarial perturbation. One famous attack is the adversarial patch, a particularly crafted sticker that makes the model mispredict the object it is placed on. This attack presents a critical threat to cyber-physical systems that rely on cameras such as autonomous cars. Despite the significance of the problem, conducting research in this setting has been difficult; evaluating attacks and defenses in the real world is exceptionally costly while synthetic data are unrealistic. In this work, we propose the REAP (REalistic Adversarial Patch) benchmark, a digital benchmark that enables the evaluations on real images under real-world conditions. Built on top of the Mapillary Vistas dataset, our benchmark contains over 14,000 traffic signs. Each sign is augmented with geometric and lighting transformations for applying a digitally generated patch realistically onto the sign. Using our benchmark, we perform the first large-scale assessments of adversarial patch attacks under realistic conditions. Our experiments suggest that patch attacks may present a smaller threat than previously believed and that the success rate of an attack on simpler digital simulations is not predictive of its actual effectiveness in practice. Our benchmark is released publicly at https://github.com/wagner-group/reap-benchmark.
引用
收藏
页码:4617 / 4628
页数:12
相关论文
共 50 条
  • [21] Towards a Large-Scale Biologically Realistic Model of the Hippocampus
    Hendrickson, Phillip J.
    Yu, Gene J.
    Robinson, Brian S.
    Song, Dong
    Berger, Theodore W.
    [J]. 2012 ANNUAL INTERNATIONAL CONFERENCE OF THE IEEE ENGINEERING IN MEDICINE AND BIOLOGY SOCIETY (EMBC), 2012, : 4595 - 4598
  • [22] Large-Scale Realistic Network Data Generation on a Budget
    Ricks, Brian
    Tague, Patrick
    Thuraisingham, Bhavani
    [J]. 2018 IEEE INTERNATIONAL CONFERENCE ON INFORMATION REUSE AND INTEGRATION (IRI), 2018, : 23 - 30
  • [23] Large-Scale Strategic Games and Adversarial Machine Learning
    Alpcan, Tansu
    Rubinstein, Benjamin I. P.
    Leckie, Christopher
    [J]. 2016 IEEE 55TH CONFERENCE ON DECISION AND CONTROL (CDC), 2016, : 4420 - 4426
  • [24] ON ADVERSARIAL ROBUSTNESS OF LARGE-SCALE AUDIO VISUAL LEARNING
    Li, Juncheng B.
    Qu, Shuhui
    Li, Xinjian
    Huang, Po-Yao
    Metze, Florian
    [J]. 2022 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH AND SIGNAL PROCESSING (ICASSP), 2022, : 231 - 235
  • [25] Attentive Adversarial Network for Large-Scale Sleep Staging
    Nasiri, Samaneh
    Clifford, Gari D.
    [J]. MACHINE LEARNING FOR HEALTHCARE CONFERENCE, VOL 126, 2020, 126 : 457 - 477
  • [26] Tenrec: A Large-scale Multipurpose Benchmark Dataset for Recommender Systems
    Yuan, Guanghu
    Yuan, Fajie
    Li, Yudong
    Kong, Beibei
    Li, Shujie
    Chen, Lei
    Yang, Min
    Yu, Chenyun
    Hu, Bo
    Li, Zang
    Xu, Yu
    Qie, Xiaohu
    [J]. ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 35, NEURIPS 2022, 2022,
  • [27] MeViS: A Large-scale Benchmark for Video Segmentation with Motion Expressions
    Ding, Henghui
    Liu, Chang
    He, Shuting
    Jiang, Xudong
    Loy, Chen Change
    [J]. 2023 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION, ICCV, 2023, : 2694 - 2703
  • [28] Evolution Gym: A Large-Scale Benchmark for Evolving Soft Robots
    Bhatia, Jagdeep Singh
    Jackson, Holly
    Tian, Yunsheng
    Xu, Jie
    Matusik, Wojciech
    [J]. ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 34 (NEURIPS 2021), 2021, 34
  • [29] FbMultiLingMisinfo: Challenging Large-Scale Multilingual Benchmark for Misinformation Detection
    Barnabo, Giorgio
    Siciliano, Federico
    Castillo, Carlos
    Leonardi, Stefano
    Nakov, Preslav
    Martino, Giovanni Da San
    Silvestri, Fabrizio
    [J]. 2022 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS (IJCNN), 2022,
  • [30] A Large-scale Benchmark Dataset for Event Recognition in Surveillance Video
    Oh, Sangmin
    Hoogs, Anthony
    Perera, Amitha
    Cuntoor, Naresh
    Chen, Chia-Chih
    Lee, Jong Taek
    Mukherjee, Saurajit
    Aggarwal, J. K.
    Lee, Hyungtae
    Davis, Larry
    Swears, Eran
    Wang, Xioyang
    Ji, Qiang
    Reddy, Kishore
    Shah, Mubarak
    Vondrick, Carl
    Pirsiavash, Hamed
    Ramanan, Deva
    Yuen, Jenny
    Torralba, Antonio
    Song, Bi
    Fong, Anesco
    Roy-Chowdhury, Amit
    Desai, Mita
    [J]. 2011 IEEE CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2011,