Papers
Topics
Authors
Recent
Gemini 2.5 Flash
Gemini 2.5 Flash
97 tokens/sec
GPT-4o
53 tokens/sec
Gemini 2.5 Pro Pro
43 tokens/sec
o3 Pro
4 tokens/sec
GPT-4.1 Pro
47 tokens/sec
DeepSeek R1 via Azure Pro
28 tokens/sec
2000 character limit reached

Leveraging Local Patch Differences in Multi-Object Scenes for Generative Adversarial Attacks (2209.09883v2)

Published 20 Sep 2022 in cs.CV

Abstract: State-of-the-art generative model-based attacks against image classifiers overwhelmingly focus on single-object (i.e., single dominant object) images. Different from such settings, we tackle a more practical problem of generating adversarial perturbations using multi-object (i.e., multiple dominant objects) images as they are representative of most real-world scenes. Our goal is to design an attack strategy that can learn from such natural scenes by leveraging the local patch differences that occur inherently in such images (e.g. difference between the local patch on the object person' and the objectbike' in a traffic scene). Our key idea is to misclassify an adversarial multi-object image by confusing the victim classifier for each local patch in the image. Based on this, we propose a novel generative attack (called Local Patch Difference or LPD-Attack) where a novel contrastive loss function uses the aforesaid local differences in feature space of multi-object scenes to optimize the perturbation generator. Through various experiments across diverse victim convolutional neural networks, we show that our approach outperforms baseline generative attacks with highly transferable perturbations when evaluated under different white-box and black-box settings.

User Edit Pencil Streamline Icon: https://streamlinehq.com
Authors (6)
  1. Abhishek Aich (18 papers)
  2. Shasha Li (57 papers)
  3. Chengyu Song (33 papers)
  4. M. Salman Asif (54 papers)
  5. Srikanth V. Krishnamurthy (16 papers)
  6. Amit K. Roy-Chowdhury (87 papers)
Citations (8)

Summary

We haven't generated a summary for this paper yet.