Defending Against Physically Realizable Attacks on Image Classification
Wu, Tong, Tong, Liang, Vorobeychik, Yevgeniy
The attacker introduces a fixed-dimension rectangle. This rectangle can be placed by the adversary anywhere in the image, and the attacker can furthermore introduce l noise inside the rectangle with an exogenously specified high bound null (for example, null 255, which effectively allows addition of arbitrary adversarial noise). This model bears some similarity to l 0 attacks, but the rectangle imposes a contiguity constraint, which reflects common physical limitations. The model is clearly abstract: in practice, for example, adversarial occlusions need not be rectangular or have fixed dimensions (for example, the eyeglass frame attack is clearly not rectangular), but at the same time cannot usually be arbitrarily superimposed on an image, as they are implemented in the physical environment. Nevertheless, the model reflects some of the most important aspects common to many physical attacks, such as stickers placed on an adversarially chosen portion of the object we wish to identify.
Sep-20-2019
- Genre:
- Research Report (0.82)
- Industry:
- Transportation (0.46)
- Information Technology > Security & Privacy (0.46)
- Technology: