Robustness of Adversarial Images Against Filters

被引:0
|
作者
Chitic, Raluca [1 ]
Deridder, Nathan [1 ]
Leprevost, Franck [1 ]
Bernard, Nicolas [2 ]
机构
[1] Univ Luxembourg, House Numbers,6 Ave Fonte, L-4364 Esch Sur Alzette, Luxembourg
[2] La Fraze, 1288 Chemin la Fraze, F-88380 Arches, France
来源
关键词
D O I
10.1007/978-3-030-85672-4_8
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
This article addresses the robustness issue of adversarial images against filters. Given an image A, that a convolutional neural network and a human both classify as belonging to a category c(A), one considers an adversarial image D that the neural network classifies in a category c(t) not equal c(A), although a human would not notice any difference between D and A. Would the application of a filter F (such as the Gaussian blur filter) to D still lead to an adversarial image F(D) that fools the neural network? To address this issue, we perform a study on VGG-16 trained on CIFAR-10, with adversarial images obtained thanks to an evolutionary algorithm run on a specific image A taken in one category of CIFAR-10. Exposed to 4 individual filters, we show that the outputted filtered adversarial images essentially do remain adversarial in some sense. We also show that combining filters may render our EA attack less effective. We therefore design a new evolutionary algorithm, whose aim is to create adversarial images that do pass the filter test, do fool VGG-16 and do remain close enough to A that a human would not notice any difference. We show that this is indeed the case by running this new algorithm on the same image A.
引用
收藏
页码:101 / 114
页数:14
相关论文
共 50 条
  • [41] Certified Robustness of Graph Neural Networks against Adversarial Structural Perturbation
    Wang, Binghui
    Jia, Jinyuan
    Cao, Xiaoyu
    Gong, Neil Zhenqiang
    [J]. KDD '21: PROCEEDINGS OF THE 27TH ACM SIGKDD CONFERENCE ON KNOWLEDGE DISCOVERY & DATA MINING, 2021, : 1645 - 1653
  • [42] On the Robustness of Neural-Enhanced Video Streaming against Adversarial Attacks
    Zhou, Qihua
    Guo, Jingcai
    Guo, Song
    Li, Ruibin
    Zhang, Jie
    Wang, Bingjie
    Xu, Zhenda
    [J]. THIRTY-EIGHTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, VOL 38 NO 15, 2024, : 17123 - 17131
  • [43] Evaluating Robustness Against Adversarial Attacks: A Representational Similarity Analysis Approach
    Liu, Chenyu
    [J]. 2023 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS, IJCNN, 2023,
  • [44] Lateralized Learning for Robustness Against Adversarial Attacks in a Visual Classification System
    Siddique, Abubakar
    Browne, Will N.
    Grimshaw, Gina M.
    [J]. GECCO'20: PROCEEDINGS OF THE 2020 GENETIC AND EVOLUTIONARY COMPUTATION CONFERENCE, 2020, : 395 - 403
  • [45] Improving Robustness Against Adversarial Attacks with Deeply Quantized Neural Networks
    Ayaz, Ferheen
    Zakariyya, Idris
    Cano, José
    Keoh, Sye Loong
    Singer, Jeremy
    Pau, Danilo
    Kharbouche-Harrari, Mounia
    [J]. arXiv, 2023,
  • [46] Improving Robustness Against Adversarial Attacks with Deeply Quantized Neural Networks
    Ayaz, Ferheen
    Zakariyya, Idris
    Cano, Jose
    Keoh, Sye Loong
    Singer, Jeremy
    Pau, Danilo
    Kharbouche-Harrari, Mounia
    [J]. 2023 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS, IJCNN, 2023,
  • [47] Robustness Against Adversarial Attacks in Neural Networks Using Incremental Dissipativity
    Aquino, Bernardo
    Rahnama, Arash
    Seiler, Peter
    Lin, Lizhen
    Gupta, Vijay
    [J]. IEEE CONTROL SYSTEMS LETTERS, 2022, 6 : 2341 - 2346
  • [48] Enhancing Robustness Against Adversarial Examples in Network Intrusion Detection Systems
    Hashemi, Mohammad J.
    Keller, Eric
    [J]. 2020 IEEE CONFERENCE ON NETWORK FUNCTION VIRTUALIZATION AND SOFTWARE DEFINED NETWORKS (NFV-SDN), 2020, : 37 - 43
  • [49] Evaluation of the Robustness against Adversarial Examples in Hardware-Trojan Detection
    [J]. Asia Pacific Conference on Postgraduate Research in Microelectronics and Electronics, 2021, 2021-November : 5 - 8
  • [50] Improving Robustness of Facial Landmark Detection by Defending against Adversarial Attacks
    Zhu, Congcong
    Li, Xiaoqiang
    Li, Jide
    Dai, Songmin
    [J]. 2021 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2021), 2021, : 11731 - 11740