Threat of Adversarial Attacks on Deep Learning in Computer Vision: A Survey
arXiv:1801.00553
Abstract
Deep learning is at the heart of the current rise of machine learning and artificial intelligence. In the field of Computer Vision, it has become the workhorse for applications ranging from self-driving cars to surveillance and security. Whereas deep neural networks have demonstrated phenomenal success (often beyond human capabilities) in solving complex problems, recent studies show that they are vulnerable to adversarial attacks in the form of subtle perturbations to inputs that lead a model to predict incorrect outputs. For images, such perturbations are often too small to be perceptible, yet they completely fool the deep learning models. Adversarial attacks pose a serious threat to the success of deep learning in practice. This fact has lead to a large influx of contributions in this direction. This article presents the first comprehensive survey on adversarial attacks on deep learning in Computer Vision. We review the works that design adversarial attacks, analyze the existence of such attacks and propose defenses against them. To emphasize that adversarial attacks are possible in practical conditions, we separately review the contributions that evaluate adversarial attacks in the real-world scenarios. Finally, we draw on the literature to provide a broader outlook of the research direction.
Incorporates feedback provided by multiple researchers
References in corpus (52)
- Distilling the Knowledge in a Neural Network
- Sequence to Sequence Learning with Neural Networks
- Caffe: Convolutional Architecture for Fast Feature Embedding
- ZOO: Zeroth Order Optimization based Black-box Attacks to Deep Neural Networks without Training Substitute Models
- Delving into Transferable Adversarial Examples and Black-box Attacks
- Towards Deep Neural Network Architectures Robust to Adversarial Examples
- Certified Defenses against Adversarial Examples
- YOLO9000: Better, Faster, Stronger
- The Space of Transferable Adversarial Examples
- Countering Adversarial Images using Input Transformations
- Generating Adversarial Malware Examples for Black-Box Attacks Based on GAN
- A Closer Look at Memorization in Deep Networks
- PixelDefend: Leveraging Generative Models to Understand and Defend against Adversarial Examples
- Improving the Adversarial Robustness and Interpretability of Deep Neural Networks by Regularizing their Input Gradients
- A study of the effect of JPG compression on adversarial images
- Mitigating Adversarial Effects Through Randomization
- Simple Black-Box Adversarial Perturbations for Deep Networks
- Houdini: Fooling Deep Structured Prediction Models
- MagNet and "Efficient Defenses Against Adversarial Attacks" are Not Robust to Adversarial Examples
- A Boundary Tilting Persepective on the Phenomenon of Adversarial Examples
- Adversarial Examples, Uncertainty, and Transfer Testing Robustness in Gaussian Process Hybrid Deep Networks
- Towards Proving the Adversarial Robustness of Deep Neural Networks
- Fast Feature Fool: A data independent approach to universal adversarial perturbations
- Biologically inspired protection of deep networks from adversarial attacks
- Provably Minimally-Distorted Adversarial Examples
- UPSET and ANGRI : Breaking High Performance Image Classifiers
- Blocking Transferability of Adversarial Examples in Black-Box Learning Systems
- Towards Interpretable Deep Neural Networks by Leveraging Adversarial Examples
- Extending Defensive Distillation
- Adversarial Example Defenses: Ensembles of Weak Defenses are not Strong
- APE-GAN: Adversarial Perturbation Elimination with GAN
- Ensemble Methods as a Defense to Adversarial Perturbations Against Deep Neural Networks
- On the Effectiveness of Defensive Distillation
- Standard detectors aren't (currently) fooled by physical adversarial stop signs
- Boosting Adversarial Attacks with Momentum
- Feature Squeezing Mitigates and Detects Carlini/Wagner Adversarial Examples
- On the Robustness of Convolutional Neural Networks to Internal Architecture and Weight Perturbations
- Adversarial examples for generative models
- Defense against Universal Adversarial Perturbations
- Intriguing Properties of Adversarial Examples
- Attacking Binarized Neural Networks
- Assessing Threat of Adversarial Examples on Deep Neural Networks
- Adversary Detection in Neural Networks via Persistent Homology
- Art of singular vectors and universal adversarial perturbations
- HyperNetworks with statistical filtering for defending adversarial examples
- Adversarial Attacks Beyond the Image Space
- Geometric robustness of deep networks: analysis and improvement
- Using Non-invertible Data Transformations to Build Adversarial-Robust Neural Networks
- Fooling Vision and Language Models Despite Localization and Attention Mechanism
- Enhanced Attacks on Defensively Distilled Deep Neural Networks
- Adversarial-Playground: A Visualization Suite Showing How Adversarial Examples Fool Deep Learning
- Butterfly Effect: Bidirectional Control of Classification Performance by Small Additive Perturbation
Cited by in corpus (48)
- Understanding Measures of Uncertainty for Adversarial Example Detection
- Training verified learners with learned verifiers
- POBA-GA: Perturbation Optimized Black-Box Adversarial Attacks via Genetic Algorithm
- Hardware Trojan Attacks on Neural Networks
- BIRADS Features-Oriented Semi-supervised Deep Learning for Breast Ultrasound Computer-Aided Diagnosis
- ME-Net: Towards Effective Adversarial Robustness with Matrix Estimation
- Defending against Adversarial Images using Basis Functions Transformations
- A Brief Survey on Autonomous Vehicle Possible Attacks, Exploits and Vulnerabilities
- Deep neural network enabled corrective source term approach to hybrid analysis and modeling
- L2-Nonexpansive Neural Networks
- Transferable Adversarial Attacks for Image and Video Object Detection
- An Improved Genetic Algorithm and Its Application in Neural Network Adversarial Attack
- Multifidelity Computing for Coupling Full and Reduced Order Models
- Defense against Universal Adversarial Perturbations
- A Noise-Sensitivity-Analysis-Based Test Prioritization Technique for Deep Neural Networks
- Attacks on State-of-the-Art Face Recognition using Attentional Adversarial Attack Generative Network
- Feature Distillation: DNN-Oriented JPEG Compression Against Adversarial Examples
- Enhancing the Robustness of Deep Neural Networks by Boundary Conditional GAN
- Robustness of Rotation-Equivariant Networks to Adversarial Perturbations
- Adversarial Defense via Data Dependent Activation Function and Total Variation Minimization
- Gradient Band-based Adversarial Training for Generalized Attack Immunity of A3C Path Finding
- Risk Bounds for Robust Deep Learning
- Featurized Bidirectional GAN: Adversarial Defense via Adversarially Learned Semantic Inference
- Attacking Vision-based Perception in End-to-End Autonomous Driving Models
- Block Switching: A Stochastic Approach for Deep Learning Security
- Mathematical Analysis of Adversarial Attacks
- Strength in Numbers: Trading-off Robustness and Computation via Adversarially-Trained Ensembles
- Feature Prioritization and Regularization Improve Standard Accuracy and Adversarial Robustness
- ATMPA: Attacking Machine Learning-based Malware Visualization Detection Methods via Adversarial Examples
- Trust but Verify: An Information-Theoretic Explanation for the Adversarial Fragility of Machine Learning Systems, and a General Defense against Adversarial Attacks
- Open DNN Box by Power Side-Channel Attack
- Amata: An Annealing Mechanism for Adversarial Training Acceleration
- A Robust Classification-autoencoder to Defend Outliers and Adversaries
- Robustifying deep networks for image segmentation
- On the randomised stability constant for inverse problems
- FineFool: Fine Object Contour Attack via Attention
- Lagrangian Objective Function Leads to Improved Unforeseen Attack Generalization in Adversarial Training
- Robust Certification for Laplace Learning on Geometric Graphs
- Augmenting Model Robustness with Transformation-Invariant Attacks
- An Information-Theoretic Explanation for the Adversarial Fragility of AI Classifiers
- Why Blocking Targeted Adversarial Perturbations Impairs the Ability to Learn
- Correlation Analysis between the Robustness of Sparse Neural Networks and their Random Hidden Structural Priors
- Robust and Information-theoretically Safe Bias Classifier against Adversarial Attacks
- An Empirical Review of Adversarial Defenses
- Localized Adversarial Training for Increased Accuracy and Robustness in Image Classification
- Physical world assistive signals for deep neural network classifiers -- neither defense nor attack
- Visualizing Representations of Adversarially Perturbed Inputs
- Adversarial Attacks on Cognitive Self-Organizing Networks: The Challenge and the Way Forward