当前位置: X-MOL 学术EURASIP J. Info. Secur. › 论文详情
Our official English website, www.x-mol.net, welcomes your feedback! (Note: you will need to create a separate account there.)
Smooth adversarial examples
EURASIP Journal on Information Security ( IF 2.5 ) Pub Date : 2020-11-17 , DOI: 10.1186/s13635-020-00112-z
Hanwei Zhang , Yannis Avrithis , Teddy Furon , Laurent Amsaleg

This paper investigates the visual quality of the adversarial examples. Recent papers propose to smooth the perturbations to get rid of high frequency artifacts. In this work, smoothing has a different meaning as it perceptually shapes the perturbation according to the visual content of the image to be attacked. The perturbation becomes locally smooth on the flat areas of the input image, but it may be noisy on its textured areas and sharp across its edges.This operation relies on Laplacian smoothing, well-known in graph signal processing, which we integrate in the attack pipeline. We benchmark several attacks with and without smoothing under a white box scenario and evaluate their transferability. Despite the additional constraint of smoothness, our attack has the same probability of success at lower distortion.

中文翻译:

平滑的对抗示例

本文研究了对抗示例的视觉质量。最近的论文提出平滑干扰以摆脱高频伪像。在这项工作中,平滑具有不同的含义,因为它根据要攻击的图像的视觉内容在感知上对扰动进行整形。扰动在输入图像的平坦区域上变得局部平滑,但在其纹理区域上可能会很吵杂,并且在其边缘上可能很锐利。此操作依赖于图信号处理中众所周知的拉普拉斯平滑,我们将其整合到攻击中管道。我们在白盒方案下对几种攻击进行了基准测试(有无平滑),并评估了它们的可传递性。尽管平滑性受到其他限制,但我们的攻击在失真较低的情况下具有相同的成功概率。
更新日期:2020-11-17
down
wechat
bug