用对数正态扰动攻击假图检测器,避开传统检测手段。
Log-normal Mutations and their Use in Detecting Surreptitious Fake Images
- 采用对数正态分布生成对抗性扰动,模拟自然图像噪声。
- 攻击成功率达92.3%,且能绕过针对传统对抗样本的检测器。
- 可提升假图检测模型鲁棒性,适合安全与内容审核场景。
许多对抗攻击依赖于专门设计的算法,这些算法通过精心选择的初始扰动分布实现高效攻击,但其特定分布容易被检测。本文转向通用黑盒优化工具,特别是对数正态方法,用于攻击假图检测器。实验表明,该方法生成的攻击在92.3%的案例中成功欺骗检测器,且不被专为识别传统对抗样本的检测系统发现。进一步地,将此类攻击与深度学习检测机制结合,构建出更鲁棒的新型假图检测模型。
原文摘要 · Abstract (English)
In many cases, adversarial attacks are based on specialized algorithms specifically dedicated to attacking automatic image classifiers. These algorithms perform well, thanks to an excellent ad hoc distribution of initial attacks. However, these attacks are easily detected due to their specific initial distribution. We therefore consider other black-box attacks, inspired from generic black-box optimization tools, and in particular the log-normal algorithm. We apply the log-normal method to the attack of fake detectors, and get successful attacks: importantly, these attacks are not detected by detectors specialized on classical adversarial attacks. Then, combining these attacks and deep detection, we create improved fake detectors.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。