All You Need is RAW: Defending Against Adversarial Attacks with Camera Image Pipelines

12/16/2021
by   Yuxuan Zhang, et al.
0

Existing neural networks for computer vision tasks are vulnerable to adversarial attacks: adding imperceptible perturbations to the input images can fool these methods to make a false prediction on an image that was correctly predicted without the perturbation. Various defense methods have proposed image-to-image mapping methods, either including these perturbations in the training process or removing them in a preprocessing denoising step. In doing so, existing methods often ignore that the natural RGB images in today's datasets are not captured but, in fact, recovered from RAW color filter array captures that are subject to various degradations in the capture. In this work, we exploit this RAW data distribution as an empirical prior for adversarial defense. Specifically, we proposed a model-agnostic adversarial defensive method, which maps the input RGB images to Bayer RAW space and back to output RGB using a learned camera image signal processing (ISP) pipeline to eliminate potential adversarial patterns. The proposed method acts as an off-the-shelf preprocessing module and, unlike model-specific adversarial training methods, does not require adversarial images to train. As a result, the method generalizes to unseen tasks without additional retraining. Experiments on large-scale datasets (e.g., ImageNet, COCO) for different vision tasks (e.g., classification, semantic segmentation, object detection) validate that the method significantly outperforms existing methods across task domains.

READ FULL TEXT

page 4

page 7

research
06/02/2022

Adversarial RAW: Image-Scaling Attack Against Imaging Pipeline

Deep learning technologies have become the backbone for the development ...
research
03/24/2023

Self-Supervised Reversed Image Signal Processing via Reference-Guided Dynamic Parameter Selection

Unprocessed sensor outputs (RAW images) potentially improve both low-lev...
research
06/23/2020

CIE XYZ Net: Unprocessing Images for Low-Level Computer Vision Tasks

Cameras currently allow access to two image states: (i) a minimally proc...
research
02/07/2021

Adversarial Imaging Pipelines

Adversarial attacks play an essential role in understanding deep neural ...
research
12/10/2019

Feature Losses for Adversarial Robustness

Deep learning has made tremendous advances in computer vision tasks such...
research
06/07/2021

Reveal of Vision Transformers Robustness against Adversarial Attacks

Attention-based networks have achieved state-of-the-art performance in m...
research
01/21/2023

Raw or Cooked? Object Detection on RAW Images

Images fed to a deep neural network have in general undergone several ha...

Please sign up or login with your details

Forgot password? Click here to reset