FoolChecker: A platform to evaluate the robustness of images against adversarial attacks

被引:7
作者
Liu Hui [1 ]
Zhao Bo [1 ]
Huang Linquan [1 ,2 ]
Guo Jiabao [1 ]
Liu Yifan [1 ]
机构
[1] Wuhan Univ, Sch Cyber Sci & Engn, Wuhan 430072, Hubei, Peoples R China
[2] Wuhan Vocat Coll Software & Engn, Informat Sch, Wuhan 430205, Hubei, Peoples R China
基金
中国国家自然科学基金;
关键词
Deep neural network; Adversarial examples; Non-robust features; Differential evolution; Greedy algorithm;
D O I
10.1016/j.neucom.2020.05.062
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Deep neural network (DNN) is inherently vulnerable to well-designed input samples called adversarial examples, which can easily alter the output of the DNN by adding slight perturbations to the input. The recent study proved that adversarial vulnerability is caused by non-robust features and is not inherently tied to DNN. The paper presents a platform called FoolChecker to evaluate the image robustness against adversarial attacks from the perspective of image itself rather than DNN models. We define the minimum perceptual distance between the original examples and the adversarial ones to quantify the robustness against adversarial attacks. Firstly, differential evolution is applied to generate candidate perturbation units with high perturbation priority. And then, the greedy algorithm tries to add the pixel with the current highest perturbation priority into perturbation units until the DNN model is fooled. Finally, the perceptual distance of perturbation units is calculated as a index to evaluate the robustness of images against adversarial attacks. Experimental results show that the FoolChecker can give proper evaluation of the robustness of images against adversarial attacks with acceptable time. (c) 2020 Published by Elsevier B.V.
引用
收藏
页码:216 / 225
页数:10
相关论文
共 30 条
[1]  
Andrew I., 2019, ARXIV190502175
[2]  
Bojarski Mariusz, 2016, arXiv
[3]  
Buckman J., 2018, ICLR
[4]   Quadruplet Network With One-Shot Learning for Fast Visual Object Tracking [J].
Dong, Xingping ;
Shen, Jianbing ;
Wu, Dongming ;
Guo, Kan ;
Jin, Xiaogang ;
Porikli, Fatih .
IEEE TRANSACTIONS ON IMAGE PROCESSING, 2019, 28 (07) :3516-3527
[5]  
Dong XW, 2018, IEEE CONF COMPUT
[6]  
Guo Chuan, 2018, ICLR
[7]  
He K., 2016, 2016 IEEE Conference on Computer Vision and Pattern Recognition (CVPR), DOI [DOI 10.1109/CVPR.2016.90, 10.1109/CVPR.2016.90]
[8]   Personalized Classifier for Food Image Recognition [J].
Horiguchi, Shota ;
Amano, Sosuke ;
Ogawa, Makoto ;
Aizawa, Kiyoharu .
IEEE TRANSACTIONS ON MULTIMEDIA, 2018, 20 (10) :2836-2848
[9]  
Huang G., 2017, Computer Vision and Pattern Recognition CVPR, P4700, DOI [DOI 10.1109/CVPR.2017.243, 10.1109/CVPR.2017.243]
[10]   Invariant Information Clustering for Unsupervised Image Classification and Segmentation [J].
Ji, Xu ;
Henriques, Joao F. ;
Vedaldi, Andrea .
2019 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2019), 2019, :9864-9873