A study of the effect of JPG compression on adversarial images
arXiv:1608.00853
Abstract
Neural network image classifiers are known to be vulnerable to adversarial images, i.e., natural images which have been modified by an adversarial perturbation specifically designed to be imperceptible to humans yet fool the classifier. Not only can adversarial images be generated easily, but these images will often be adversarial for networks trained on disjoint subsets of data or with different architectures. Adversarial images represent a potential security risk as well as a serious machine learning challenge---it is clear that vulnerable neural networks perceive images very differently from humans. Noting that virtually every image classification data set is composed of JPG images, we evaluate the effect of JPG compression on the classification of adversarial images. For Fast-Gradient-Sign perturbations of small magnitude, we found that JPG compression often reverses the drop in classification accuracy to a large extent, but not always. As the magnitude of the perturbations increases, JPG recompression alone is insufficient to reverse the effect.
8 pages, 4 figures
References in corpus (2)
Cited by in corpus (61)
- Countering Adversarial Images using Input Transformations
- Explainable Artificial Intelligence Applications in Cyber Security: State-of-the-Art in Research
- Invisible for both Camera and LiDAR: Security of Multi-Sensor Fusion based Perception in Autonomous Driving Under Physical-World Attacks
- CycleGAN, a Master of Steganography
- advertorch v0.1: An Adversarial Robustness Toolbox based on PyTorch
- How Deep Learning Sees the World: A Survey on Adversarial Attacks & Defenses
- Adversarial Examples Are a Natural Consequence of Test Error in Noise
- Blocking Transferability of Adversarial Examples in Black-Box Learning Systems
- Adversarial Examples in Modern Machine Learning: A Review
- A Survey on Security Attacks and Defense Techniques for Connected and Autonomous Vehicles
- ConFoc: Content-Focus Protection Against Trojan Attacks on Neural Networks
- A Survey of Black-Box Adversarial Attacks on Computer Vision Models
- Benchmarking Adversarial Robustness
- AdvDrop: Adversarial Attack to DNNs by Dropping Information
- Transferability of Adversarial Examples to Attack Cloud-based Image Classifier Service
- Adversarial Examples on Object Recognition: A Comprehensive Survey
- Efficiency-driven Hardware Optimization for Adversarially Robust Neural Networks
- On the Limitations of Denoising Strategies as Adversarial Defenses
- Adversarial Perturbations Prevail in the Y-Channel of the YCbCr Color Space
- Adversarial Feature Augmentation and Normalization for Visual Recognition
- Generative Dynamic Patch Attack
- A Person Re-identification Data Augmentation Method with Adversarial Defense Effect
- Improving Global Adversarial Robustness Generalization With Adversarially Trained GAN
- Staircase Sign Method for Boosting Adversarial Attacks
- CAP-GAN: Towards Adversarial Robustness with Cycle-consistent Attentional Purification
- Detecting Localized Adversarial Examples: A Generic Approach using Critical Region Analysis
- Regularizers for Single-step Adversarial Training
- SoK: How Robust is Image Classification Deep Neural Network Watermarking? (Extended Version)
- MagDR: Mask-guided Detection and Reconstruction for Defending Deepfakes
- Fast Gradient Non-sign Methods
- Exposing the Robustness and Vulnerability of Hybrid 8T-6T SRAM Memory Architectures to Adversarial Attacks in Deep Neural Networks
- Analytical Moment Regularizer for Gaussian Robust Networks
- Defending Adversarial Attacks by Correcting logits
- Feature-Filter: Detecting Adversarial Examples through Filtering off Recessive Features
- Medical Aegis: Robust adversarial protectors for medical images
- Perceptually Constrained Adversarial Attacks
- Noise Optimization for Artificial Neural Networks
- Multi-objective Search of Robust Neural Architectures against Multiple Types of Adversarial Attacks
- Anti-Bandit Neural Architecture Search for Model Defense
- A Frequency Perspective of Adversarial Robustness
- Convolutional Neural Networks with Transformed Input based on Robust Tensor Network Decomposition
- Moving Target Defense for Deep Visual Sensing against Adversarial Examples
- Dompteur: Taming Audio Adversarial Examples
- MixDefense: A Defense-in-Depth Framework for Adversarial Example Detection Based on Statistical and Semantic Analysis
- DetectX -- Adversarial Input Detection using Current Signatures in Memristive XBar Arrays
- Meta Gradient Adversarial Attack
- Transferable Adversarial Examples for Anchor Free Object Detection
- Fast Local Attack: Generating Local Adversarial Examples for Object Detectors
- Human Imperceptible Attacks and Applications to Improve Fairness
- Context-Aware Image Denoising with Auto-Threshold Canny Edge Detection to Suppress Adversarial Perturbation
- Adaptive Perturbation for Adversarial Attack
- Defense-friendly Images in Adversarial Attacks: Dataset and Metrics for Perturbation Difficulty
- Adversarial Robustness Across Representation Spaces
- Towards Natural Robustness Against Adversarial Examples
- On Intrinsic Dataset Properties for Adversarial Machine Learning
- Defenses Against Multi-Sticker Physical Domain Attacks on Classifiers
- Multi-granularity Textual Adversarial Attack with Behavior Cloning
- Mitigating large adversarial perturbations on X-MAS (X minus Moving Averaged Samples)
- On Brightness Agnostic Adversarial Examples Against Face Recognition Systems
- Countering Adversarial Examples: Combining Input Transformation and Noisy Training
- Moiré Attack (MA): A New Potential Risk of Screen Photos