Perceptual Evaluation of Adversarial Attacks for CNN-based Image Classification

被引:10
|
作者
Fezza, Sid Ahmed [1 ,2 ]
Bakhti, Yassine [1 ,2 ,3 ]
Hamidouche, Wassim [3 ]
Deforges, Olivier [3 ]
机构
[1] Natl Inst Telecommun, Oran, Algeria
[2] ICT, Oran, Algeria
[3] Univ Rennes, CNRS, UMR 6164, INSA Rennes,IETR, Rennes, France
关键词
deep neural network; adversarial attack; adversarial example; subjective evaluation; perturbation; QUALITY ASSESSMENT; INFORMATION;
D O I
10.1109/qomex.2019.8743213
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Deep neural networks (DNNs) have recently achieved state-of-the-art performance and provide significant progress in many machine learning tasks, such as image classification, speech processing, natural language processing, etc. However, recent studies have shown that DNNs are vulnerable to adversarial attacks. For instance, in the image classification domain, adding small imperceptible perturbations to the input image is sufficient to fool the DNN and to cause misclassification. The perturbed image, called adversarial example, should be visually as close as possible to the original image. However, all the works proposed in the literature for generating adversarial examples have used the L-p norms (L-0, L-2 and L-infinity) as distance metrics to quantify the similarity between the original image and the adversarial example. Nonetheless, the L-p norms do not correlate with human judgment, making them not suitable to reliably assess the perceptual similarity/fidelity of adversarial examples. In this paper, we present a database for visual fidelity assessment of adversarial examples. We describe the creation of the database and evaluate the performance of fifteen state-of-the-art full-reference (FR) image fidelity assessment metrics that could substitute L-p norms. The database as well as subjective scores are publicly available to help designing new metrics for adversarial examples and to facilitate future research works.(1)
引用
收藏
页数:6
相关论文
共 50 条
  • [1] Analysis of Adversarial Attacks against CNN-based Image Forgery Detectors
    Gragnaniello, Diego
    Marra, Francesco
    Poggi, Giovanni
    Verdoliva, Luisa
    [J]. 2018 26TH EUROPEAN SIGNAL PROCESSING CONFERENCE (EUSIPCO), 2018, : 967 - 971
  • [2] Adversarial Examples for CNN-Based SAR Image Classification: An Experience Study
    Li, Haifeng
    Huang, Haikuo
    Chen, Li
    Peng, Jian
    Huang, Haozhe
    Cui, Zhenqi
    Mei, Xiaoming
    Wu, Guohua
    [J]. IEEE JOURNAL OF SELECTED TOPICS IN APPLIED EARTH OBSERVATIONS AND REMOTE SENSING, 2021, 14 : 1333 - 1347
  • [3] CNN-Based Adversarial Embedding for Image Steganography
    Tang, Weixuan
    Li, Bin
    Tan, Shunquan
    Barni, Mauro
    Huang, Jiwu
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2019, 14 (08) : 2074 - 2087
  • [4] Robustness Analysis of CNN-based Malware Family Classification Methods against Various Adversarial Attacks
    Choi, Seok-Hwan
    Shin, Jin-Myeong
    Liu, Peng
    Choi, Yoon-Ho
    [J]. 2019 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY (CNS), 2019,
  • [5] CNN-Based Ternary Classification for Image Steganalysis
    Kang, Sanghoon
    Park, Hanhoon
    Park, Jong-Il
    [J]. ELECTRONICS, 2019, 8 (11)
  • [6] ON THE TRANSFERABILITY OF ADVERSARIAL EXAMPLES AGAINST CNN-BASED IMAGE FORENSICS
    Barni, M.
    Kallas, K.
    Nowroozi, E.
    Tondi, B.
    [J]. 2019 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH AND SIGNAL PROCESSING (ICASSP), 2019, : 8286 - 8290
  • [7] A novel CNN-based approach for detection and classification of DDoS attacks
    Najar, Ashfaq Ahmad
    Sugali, Manohar Naik
    Lone, Faisal Rasheed
    Nazir, Azra
    [J]. CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2024, 36 (19):
  • [8] CNN-Based Malware Family Classification and Evaluation
    Hebish, Mohamed Wael
    Awni, Mohamed
    [J]. 2024 14TH INTERNATIONAL CONFERENCE ON ELECTRICAL ENGINEERING, ICEENG 2024, 2024, : 219 - 224
  • [9] CNN-based Large Scale Landsat Image Classification
    Zhao, Xuemei
    Gao, Lianru
    Chen, Zhengchao
    Zhang, Bing
    Liao, Wenzhi
    [J]. 2018 ASIA-PACIFIC SIGNAL AND INFORMATION PROCESSING ASSOCIATION ANNUAL SUMMIT AND CONFERENCE (APSIPA ASC), 2018, : 611 - 617
  • [10] Image Classification with CNN-based Fisher Vector Coding
    Song, Yan
    Hong, Xinhai
    McLoughlin, Ian
    Dai, Lirong
    [J]. 2016 30TH ANNIVERSARY OF VISUAL COMMUNICATION AND IMAGE PROCESSING (VCIP), 2016,