Adversarial Attacks on Scene Graph Generation

被引:1
|
作者
Zhao, Mengnan [1 ]
Zhang, Lihe [2 ]
Wang, Wei [3 ]
Kong, Yuqiu [1 ]
Yin, Baocai [1 ]
机构
[1] Dalian Univ Technol, Sch Comp Sci & Technol, Dalian 116000, Peoples R China
[2] Dalian Univ Technol, Sch Informat & Commun Engn, Dalian 116024, Peoples R China
[3] Chinese Acad Sci, Inst Automat, Natl Lab Pattern Recognit, Beijing 100080, Peoples R China
关键词
Task analysis; Object detection; Windows; Visualization; Mirrors; Predictive models; Perturbation methods; Scene graph generation; adversarial attack; bounding box relabeling; two-step weighted attack; NETWORK;
D O I
10.1109/TIFS.2024.3360880
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Scene graph generation (SGG) effectively improves semantic understanding of the visual world. However, the recent interest of researchers focuses on enhancing SGG in non-adversarial settings, which raises our curiosity about the adversarial robustness of SGG models. To bridge this gap, we perform adversarial attacks on two typical SGG tasks, Scene Graph Detection (SGDet) and Scene Graph Classification (SGCls). Specifically, we initially propose a bounding box relabeling method to reconstruct reasonable attack targets for SGCls. It solves the inconsistency between the specified bounding boxes and the scene graphs selected as attack targets. Subsequently, we introduce a two-step weighted attack by removing the predicted objects and relational triples that affect attack performance, which significantly increases the success rate of adversarial attacks on two SGG tasks. Extensive experiments demonstrate the effectiveness of our methods on five popular SGG models and four adversarial attacks.
引用
收藏
页码:3210 / 3225
页数:16
相关论文
共 50 条
  • [41] Graph-LSTM with Global Attribute for Scene Graph Generation
    Shao, Tong
    Wu, Dapeng Oliver
    Journal of Physics: Conference Series, 2021, 2003 (01)
  • [42] DeepEC: Adversarial attacks against graph structure prediction models
    Xian, Xingping
    Wu, Tao
    Qiao, Shaojie
    Wang, Wei
    Wang, Chao
    Liu, Yanbing
    Xu, Guangxia
    NEUROCOMPUTING, 2021, 437 : 168 - 185
  • [43] UnboundAttack: Generating Unbounded Adversarial Attacks to Graph Neural Networks
    Ennadir, Sofiane
    Alkhatib, Amr
    Nikolentzos, Giannis
    Vazirgiannis, Michalis
    Bostrom, Henrik
    COMPLEX NETWORKS & THEIR APPLICATIONS XII, VOL 1, COMPLEX NETWORKS 2023, 2024, 1141 : 100 - 111
  • [44] Dynamic Gated Graph Neural Networks for Scene Graph Generation
    Khademi, Mahmoud
    Schulte, Oliver
    COMPUTER VISION - ACCV 2018, PT VI, 2019, 11366 : 669 - 685
  • [45] Atom correlation based graph propagation for scene graph generation
    Lin, Bingqian
    Zhu, Yi
    Liang, Xiaodan
    PATTERN RECOGNITION, 2022, 122
  • [46] Semantically Adversarial Scene Generation With Explicit Knowledge Guidance
    Ding, Wenhao
    Lin, Haohong
    Li, Bo
    Zhao, Ding
    IEEE TRANSACTIONS ON INTELLIGENT TRANSPORTATION SYSTEMS, 2025, 26 (02) : 1510 - 1521
  • [47] Two-level adversarial attacks for graph neural networks
    Song, Chengxi
    Niu, Lingfeng
    Lei, Minglong
    INFORMATION SCIENCES, 2024, 654
  • [48] Towards More Practical Adversarial Attacks on Graph Neural Networks
    Ma, Jiaqi
    Ding, Shuangrui
    Mei, Qiaozhu
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 33, NEURIPS 2020, 2020, 33
  • [49] GNNGUARD: Defending Graph Neural Networks against Adversarial Attacks
    Zhang, Xiang
    Zitnik, Marinka
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 33, NEURIPS 2020, 2020, 33
  • [50] Disttack: Graph Adversarial Attacks Toward Distributed GNN Training
    Zhang, Yuxiang
    Liu, Xin
    Wu, Meng
    Yan, Wei
    Yan, Mingyu
    Ye, Xiaochun
    Fan, Dongrui
    EURO-PAR 2024: PARALLEL PROCESSING, PART II, EURO-PAR 2024, 2024, 14802 : 302 - 316