Adversarial Examples for Semantic Segmentation and Object Detection
arXiv:1703.08603
Abstract
It has been well demonstrated that adversarial examples, i.e., natural images with visually imperceptible perturbations added, generally exist for deep networks to fail on image classification. In this paper, we extend adversarial examples to semantic segmentation and object detection which are much more difficult. Our observation is that both segmentation and detection are based on classifying multiple targets on an image (e.g., the basic target is a pixel or a receptive field in segmentation, and an object proposal in detection), which inspires us to optimize a loss function over a set of pixels/proposals for generating adversarial perturbations. Based on this idea, we propose a novel algorithm named Dense Adversary Generation (DAG), which generates a large family of adversarial examples, and applies to a wide range of state-of-the-art deep networks for segmentation and detection. We also find that the adversarial perturbations can be transferred across networks with different training data, based on different architectures, and even for different recognition tasks. In particular, the transferability across networks with the same architecture is more significant than in other cases. Besides, summing up heterogeneous perturbations often leads to better transfer performance, which provides an effective method of black-box adversarial attack.
To appear in ICCV 2017
References in corpus (13)
- DeCAF: A Deep Convolutional Activation Feature for Generic Visual Recognition
- R-FCN: Object Detection via Region-based Fully Convolutional Networks
- Ensemble Adversarial Training: Attacks and Defenses
- The Cityscapes Dataset for Semantic Urban Scene Understanding
- Delving into Transferable Adversarial Examples and Black-box Attacks
- DeepLab: Semantic Image Segmentation with Deep Convolutional Nets, Atrous Convolution, and Fully Connected CRFs
- CNN Features off-the-shelf: an Astounding Baseline for Recognition
- Adversarial Machine Learning at Scale
- Holistically-Nested Edge Detection
- Foveation-based Mechanisms Alleviate Adversarial Examples
- Practical Black-Box Attacks against Machine Learning
- Adversarial Examples for Semantic Image Segmentation
- Unsupervised learning of object semantic parts from internal states of CNNs by population encoding
Cited by in corpus (49)
- Robust Physical-World Attacks on Deep Learning Models
- AdvHat: Real-world adversarial attack on ArcFace Face ID system
- Adversarial Examples: Attacks and Defenses for Deep Learning
- MagNet: a Two-Pronged Defense against Adversarial Examples
- Threat of Adversarial Attacks on Deep Learning in Computer Vision: A Survey
- Houdini: Fooling Deep Structured Prediction Models
- Towards Fast Computation of Certified Robustness for ReLU Networks
- RobustBench: a standardized adversarial robustness benchmark
- Physical Adversarial Examples for Object Detectors
- UPSET and ANGRI : Breaking High Performance Image Classifiers
- Robust Adversarial Perturbation on Deep Proposal-based Models
- Contrastive Learning with Adversarial Examples
- Adversarial Examples in Modern Machine Learning: A Review
- Recent Advances in Adversarial Training for Adversarial Robustness
- DeepBillboard: Systematic Physical-World Testing of Autonomous Driving Systems
- Adversarially Robust Neural Architectures
- Detecting Adversarial Attacks on Neural Network Policies with Visual Foresight
- Daedalus: Breaking Non-Maximum Suppression in Object Detection via Adversarial Examples
- Transferable Adversarial Attacks for Image and Video Object Detection
- Towards a Robust Deep Neural Network in Texts: A Survey
- Deep Co-Training for Semi-Supervised Image Recognition
- Defense against Universal Adversarial Perturbations
- Deep Nets: What have they ever done for Vision?
- Sparse Adversarial Perturbations for Videos
- Adversarial Color Enhancement: Generating Unrestricted Adversarial Images by Optimizing a Color Filter
- Metamorphic Relation Based Adversarial Attacks on Differentiable Neural Computer
- Verification of Neural Network Control Policy Under Persistent Adversarial Perturbation
- Learning Transferable Adversarial Examples via Ghost Networks
- Local Black-box Adversarial Attacks: A Query Efficient Approach
- Exploring the Robustness of NMT Systems to Nonsensical Inputs
- Evaluation of Momentum Diverse Input Iterative Fast Gradient Sign Method (M-DI2-FGSM) Based Attack Method on MCS 2018 Adversarial Attacks on Black Box Face Recognition System
- Enhancing Cross-task Black-Box Transferability of Adversarial Examples with Dispersion Reduction
- Adversarial Metric Attack and Defense for Person Re-identification
- Fooling Vision and Language Models Despite Localization and Attention Mechanism
- UnrealStereo: Controlling Hazardous Factors to Analyze Stereo Vision
- Adversarial Visual Robustness by Causal Intervention
- Frequency-Tuned Universal Adversarial Attacks
- Monocular Depth Estimators: Vulnerabilities and Attacks
- Trust but Verify: An Information-Theoretic Explanation for the Adversarial Fragility of Machine Learning Systems, and a General Defense against Adversarial Attacks
- Butterfly Effect: Bidirectional Control of Classification Performance by Small Additive Perturbation
- Defending Adversarial Attacks by Correcting logits
- An Alarm System For Segmentation Algorithm Based On Shape Model
- Towards Query-Efficient Black-Box Adversary with Zeroth-Order Natural Gradient Descent
- FineFool: Fine Object Contour Attack via Attention
- A New Ensemble Adversarial Attack Powered by Long-term Gradient Memories
- Fashion-Guided Adversarial Attack on Person Segmentation
- Model-Agnostic Defense for Lane Detection against Adversarial Attack
- Towards Stable Adversarial Feature Learning for LiDAR based Loop Closure Detection
- Using LIP to Gloss Over Faces in Single-Stage Face Detection Networks