arXiv:2409.03458cs.CV2024-09被引 4

用不均匀光照扰动图像,暴露并提升模型抗攻击能力

Non-Uniform Illumination Attack for Fooling Convolutional Neural Networks

  • 设计可变的非均匀光照掩码,对图像进行隐蔽扰动
  • 在多个数据集上使主流模型准确率下降超30%
  • 将扰动图像加入训练集,显著提升模型鲁棒性

卷积神经网络(CNN)虽取得显著进展,但仍易受人类难以察觉的微小图像扰动影响。本文提出一种新型非均匀光照(NUI)攻击方法,通过使用不同NUI掩码对图像进行细微修改。在CIFAR10、TinyImageNet和CalTech256等常用数据集上,针对VGG、ResNet、MobilenetV3-small和InceptionV3等模型,评估了12种NUI攻击模型的性能。实验显示,受NUI攻击后,模型分类准确率显著下降。为应对该问题,提出将NUI扰动图像加入训练集的防御策略,结果表明模型在面对真实扰动时性能大幅提升,有效增强了对非均匀光照攻击的抵抗力。

原文摘要 · Abstract (English)

Convolutional Neural Networks (CNNs) have made remarkable strides; however, they remain susceptible to vulnerabilities, particularly in the face of minor image perturbations that humans can easily recognize. This weakness, often termed as 'attacks', underscores the limited robustness of CNNs and the need for research into fortifying their resistance against such manipulations. This study introduces a novel Non-Uniform Illumination (NUI) attack technique, where images are subtly altered using varying NUI masks. Extensive experiments are conducted on widely-accepted datasets including CIFAR10, TinyImageNet, and CalTech256, focusing on image classification with 12 different NUI attack models. The resilience of VGG, ResNet, MobilenetV3-small and InceptionV3 models against NUI attacks are evaluated. Our results show a substantial decline in the CNN models' classification accuracy when subjected to NUI attacks, indicating their vulnerability under non-uniform illumination. To mitigate this, a defense strategy is proposed, including NUI-attacked images, generated through the new NUI transformation, into the training set. The results demonstrate a significant enhancement in CNN model performance when confronted with perturbed images affected by NUI attacks. This strategy seeks to bolster CNN models' resilience against NUI attacks.

对抗攻击光照扰动模型鲁棒性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。