Poisoning Attacks against Feature-Based Image Classification

被引:2
|
作者
Mayerhofer, Robin [1 ]
Mayer, Rudolf [1 ,2 ]
机构
[1] Vienna Univ Technol, Vienna, Austria
[2] SBA Res gGmbH, Vienna, Austria
关键词
Adversarial machine learning; Poisoning attacks; Feature-Based Image Classification;
D O I
10.1145/3508398.3519363
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Adversarial machine learning and the robustness of machine learning is gaining attention, especially in image classification. Attacks based on data poisoning, with the aim to lower the integrity or availability of a model, showed high success rates, while barely reducing the classifiers accuracy - particularly against Deep Learning approaches such as Convolutional Neural Networks (CNNs). While Deep Learning has become the most prominent technique for many pattern recognition tasks, feature-extraction based systems still have their applications - and there is surprisingly little research dedicated to the vulnerability of those approaches. We address this gap and show preliminary results in evaluating poisoning attacks against feature-extraction based systems, and compare them to CNNs, on a traffic sign classification dataset. Our findings show that feature-extraction based ML systems require higher poisoning percentages to achieve similar backdoor success, and also need a consistent (static) backdoor position to work.
引用
收藏
页码:358 / 360
页数:3
相关论文
共 50 条
  • [1] A Feature-based Robust Digital Image Watermarking Against Desynchronization Attacks
    Xiang-Yang Wang~(1
    [J]. Machine Intelligence Research, 2007, (04) : 428 - 432
  • [2] A feature-based robust digital image watermarking against geometric attacks
    Wang, Xiang-yang
    Hou, Li-min
    Wu, Jun
    [J]. IMAGE AND VISION COMPUTING, 2008, 26 (07) : 980 - 989
  • [3] A feature-based robust digital image watermarking against desynchronization attacks
    Wang X.-Y.
    Wu J.
    [J]. International Journal of Automation and Computing, 2007, 4 (4) : 428 - 432
  • [4] Geometric feature-based skin image classification
    Yang, Jinfeng
    Shi, Yihua
    Xiao, Mingliang
    [J]. ADVANCED INTELLIGENT COMPUTING THEORIES AND APPLICATIONS: WITH ASPECTS OF THEORETICAL AND METHODOLOGICAL ISSUES, 2007, 4681 : 1158 - +
  • [5] A feature-based classification technique for blind image steganalysis
    Lie, WN
    Lin, GS
    [J]. IEEE TRANSACTIONS ON MULTIMEDIA, 2005, 7 (06) : 1007 - 1020
  • [6] Variational Mode Feature-Based Hyperspectral Image Classification
    Nechikkat, Nikitha
    Sowmya, V.
    Soman, K. P.
    [J]. PROCEEDINGS OF THE SECOND INTERNATIONAL CONFERENCE ON COMPUTER AND COMMUNICATION TECHNOLOGIES, IC3T 2015, VOL 2, 2016, 380 : 365 - 373
  • [7] A Feature-Based Digital Image Watermarking Algorithm Resisting to Geometrical Attacks
    Tang Wenliang
    [J]. PROCEEDINGS OF THE SECOND INTERNATIONAL SYMPOSIUM ON ELECTRONIC COMMERCE AND SECURITY, VOL I, 2009, : 174 - 178
  • [8] Is blind image steganalysis practical using feature-based classification?
    Ahd Aljarf
    Haneen Zamzami
    Adnan Gutub
    [J]. Multimedia Tools and Applications, 2024, 83 : 4579 - 4612
  • [9] Feature-Based Image Patch Approximation for Lung Tissue Classification
    Song, Yang
    Cai, Weidong
    Zhou, Yun
    Feng, David Dagan
    [J]. IEEE TRANSACTIONS ON MEDICAL IMAGING, 2013, 32 (04) : 797 - 808
  • [10] Is blind image steganalysis practical using feature-based classification?
    Aljarf, Ahd
    Zamzami, Haneen
    Gutub, Adnan
    [J]. MULTIMEDIA TOOLS AND APPLICATIONS, 2023, 83 (2) : 4579 - 4612