Generating Adversarial Images in Quantized Domains

被引:9
|
作者
Bonnet, Benoit [1 ]
Furon, Teddy [1 ]
Bas, Patrick [2 ]
机构
[1] Univ Rennes, CNRS, IRISA, INRIA, F-35000 Rennes, France
[2] Ecole Cent Lille, CRIStAL Lab, CNRS, UMR 9189, F-59650 Lille, France
关键词
Computational and artificial intelligence; neural networks; feedforward neural network; multi-layer neural network; signal processing; quantization (signal); COMPRESSION;
D O I
10.1109/TIFS.2021.3138616
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Many adversarial attacks produce floating-point tensors which are no longer adversarial when converted to raster or JPEG images due to rounding. This paper proposes a method dedicated to quantize adversarial perturbations. This "smart" quantization is conveniently implemented as versatile post-processing. It can be used on top of any white-box attack targeting any model. Its principle is tantamount to a constrained optimization problem aiming to minimize the quantization error while keeping the image adversarial after quantization. A Lagrangian formulation is proposed and an appropriate search of the Lagrangian multiplier enables to increase the success rate. We also add a control mechanism of the l(infinity)-distortion. Our method operates in both spatial and JPEG domains with little complexity. This study shows that forging adversarial images is not a hard constraint: our quantization does not introduce any extra distortion. Moreover, adversarial images quantized as JPEG also challenge defenses relying on the robustness of neural networks against JPEG compression.
引用
收藏
页码:373 / 385
页数:13
相关论文
共 50 条
  • [41] Target-X: An Efficient Algorithm for Generating Targeted Adversarial Images to Fool Neural Networks
    Khamaiseh, Sather Y.
    Bagagem, Derek
    Al-Alaj, Abdullah
    Mancino, Mathew
    Alomari, Hakem
    Aleroud, Ahmed
    2023 IEEE 47TH ANNUAL COMPUTERS, SOFTWARE, AND APPLICATIONS CONFERENCE, COMPSAC, 2023, : 617 - 626
  • [42] Super-Resolution Reconstruction of Optical Coherence Tomography Retinal Images by Generating Adversarial Network
    Ke Shuting
    Chen Minghui
    Zheng Zexi
    Yuan Yuan
    Wang Teng
    He Longxi
    Lu Linjie
    Sun Hao
    CHINESE JOURNAL OF LASERS-ZHONGGUO JIGUANG, 2022, 49 (15):
  • [43] Generating High-Resolution Fire Images with Controllable Attributes via Generative Adversarial Networks
    Nguyen Quoc Dung
    Kim, Hakil
    2022 22ND INTERNATIONAL CONFERENCE ON CONTROL, AUTOMATION AND SYSTEMS (ICCAS 2022), 2022, : 348 - 353
  • [44] QUANTIZED SYMMETRY OF LIQUID MONOLAYER DOMAINS
    LEE, KYC
    MCCONNELL, HM
    JOURNAL OF PHYSICAL CHEMISTRY, 1993, 97 (37): : 9532 - 9539
  • [45] Generating synthetic medical images with limited data using auxiliary classifier generative adversarial network: a study on thyroid ultrasound images
    Atri, Hamidreza
    Shadi, Mahdieh
    Sargolzaei, Mahdi
    JOURNAL OF ULTRASOUND, 2024, 27 (01) : 105 - 121
  • [46] Generating synthetic medical images with limited data using auxiliary classifier generative adversarial network: a study on thyroid ultrasound images
    Hamidreza Atri
    Mahdieh Shadi
    Mahdi Sargolzaei
    Journal of Ultrasound, 2024, 27 : 105 - 121
  • [47] Adversarial transformation network with adaptive perturbations for generating adversarial examples
    Zhang, Guoyin
    Da, Qingan
    Li, Sizhao
    Sun, Jianguo
    Wang, Wenshan
    Hu, Qing
    Lu, Jiashuai
    INTERNATIONAL JOURNAL OF BIO-INSPIRED COMPUTATION, 2022, 20 (02) : 94 - 103
  • [48] Generating Adversarial Examples With Distance Constrained Adversarial Imitation Networks
    Tang, Pengfei
    Wang, Wenjie
    Lou, Jian
    Xiong, Li
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2022, 19 (06) : 4145 - 4155
  • [49] Generating X-ray Images from Point Clouds Using Conditional Generative Adversarial Networks
    Haiderbhai, Mustafa
    Ledesma, Sergio
    Navab, Nassir
    Fallavollita, Pascal
    42ND ANNUAL INTERNATIONAL CONFERENCES OF THE IEEE ENGINEERING IN MEDICINE AND BIOLOGY SOCIETY: ENABLING INNOVATIVE TECHNOLOGIES FOR GLOBAL HEALTHCARE EMBC'20, 2020, : 1588 - 1591
  • [50] Enhanced Cycle Generative Adversarial Network for Generating Face Images of Untrained Races and Ages for Age Estimation
    Kim, Yu Hwan
    Nam, Se Hyun
    Park, Kang Ryoung
    IEEE ACCESS, 2021, 9 : 6087 - 6112