Disruption of Object Recognition Systems

被引:0
|
作者
Das, Utsav [1 ]
Gupta, Aman [1 ]
Bagga, Onkar Singh [1 ]
Sabnis, Manoj [1 ]
机构
[1] Vivekanand Educ Soc, Dept Informat Technol, Inst Technol, Mumbai, Maharashtra, India
关键词
Object recognition; Deep learning; Adversarial attacks;
D O I
10.1007/978-3-030-30465-2_56
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
In recent times, deep neural networks are being used in a wide variety of applications such as autonomous vehicles, medical imaging and surveillance. While they are becoming increasingly powerful, it is possible to disrupt their task by crafting adversarial inputs. These inputs are essentially perturbations added to the original inputs so that the application using the network, such as an object recognizer, is unable to classify the object in the image. Crafting such inputs to disrupt such a recognition task is termed an adversarial attack. Here, we implement two disruption strategies, Fast Gradient Sign Method (FGSM) and generating perturbations using a generator network. While FGSM requires access to the gradient calculated by the classifier with respect to the input image, the generator trains simultaneously with the classifier network to learn how to craft perturbations. Once the generator network is trained with a particular classifier (say, VGG16), it can disrupt other classifier networks in a black-box fashion as well. Using the same dataset, in this case CIFAR-10, it is possible to adversarially train the classifier to make it more robust to perturbed images. This involves training the classifier on the CIFAR-10 images with both the original images and the ones perturbed by the generator. In experiments, the attack using the generator achieves higher disruption accuracies than FGSM on very deep networks.
引用
收藏
页码:506 / 513
页数:8
相关论文
共 50 条
  • [1] Disruption of early face recognition processes by object substitution masking
    Reiss, Jason E.
    Hoffman, James E.
    VISUAL COGNITION, 2007, 15 (07) : 789 - 798
  • [2] Comparison Computerized Object Recognition Systems
    Sert, E.
    Pinar, Y.
    Taskin, D.
    Taskin, C.
    Topcubasi, N.
    AMA-AGRICULTURAL MECHANIZATION IN ASIA AFRICA AND LATIN AMERICA, 2013, 44 (04): : 50 - 56
  • [3] The concrete object recognition by multispectral systems
    Zlotnikov, KA
    INTELLIGENT SYSTEMS IN DESIGN AND MANUFACTURING, 1998, 3517 : 356 - 364
  • [4] Smart Assistance Systems for Terrain and Object Recognition
    Eva Neumann
    Kevin Hirsch
    Uwe Westermeier
    ATZoffhighway worldwide, 2018, 11 (1): : 36 - 39
  • [5] Eigenviews for object recognition in multispectral imaging systems
    Ramanath, R
    Snyder, WE
    Qi, HR
    32ND APPLIED IMAGERY PATTERN RECOGNITION WORKSHOP, PROCEEDINGS, 2004, : 33 - 38
  • [6] Disruption of spatial but not object-recognition memory by neurotoxic lesions of the dorsal hippocampus in rats
    Duva, CA
    Floresco, SB
    Wunderlich, GR
    Lao, TL
    Pinel, JPJ
    Phillips, AG
    BEHAVIORAL NEUROSCIENCE, 1997, 111 (06) : 1184 - 1196
  • [7] Visual object recognition for mobile tourist information systems
    Paletta, L
    Fritz, G
    Seifert, C
    Luley, P
    Almer, A
    MULTIMEDIA ON MOBILE DEVICES, 2005, 5684 : 190 - 197
  • [8] OBJECT RECOGNITION AND POSE DETERMINATION IN MULTISENSOR ROBOTIC SYSTEMS
    TRIVEDI, MM
    ABIDI, MA
    EASON, RO
    GONZALEZ, RC
    1989 IEEE INTERNATIONAL CONFERENCE ON SYSTEMS, MAN, AND CYBERNETICS, VOLS 1-3: CONFERENCE PROCEEDINGS, 1989, : 186 - 193
  • [9] Bayesian Online Learning for MEC Object Recognition Systems
    Galanopoulos, Apostolos
    Ayala-Romero, Jose A.
    Iosifidis, George
    Leith, Douglas J.
    2020 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2020,
  • [10] Object Reading: Text Recognition for Object Recognition
    Karaoglu, Sezer
    van Gemert, Jan C.
    Gevers, Theo
    COMPUTER VISION - ECCV 2012, PT III, 2012, 7585 : 456 - 465