Beyond Pixel Norm-Balls: Parametric Adversaries using an Analytically Differentiable Renderer

08/08/2018
by   Hsueh-Ti Derek Liu, et al.
0

Many machine learning image classifiers are vulnerable to adversarial attacks, inputs with perturbations designed to intentionally trigger misclassification. Current adversarial methods directly alter pixel colors and evaluate against pixel norm-balls: pixel perturbations smaller than a specified magnitude, according to a measurement norm. This evaluation, however, has limited practical utility since perturbations in the pixel space do not correspond to underlying real-world phenomena of image formation that lead to them and has no security motivation attached. Pixels in natural images are measurements of light that has interacted with the geometry of a physical scene. As such, we propose the direct perturbation of physical parameters that underly image formation: lighting and geometry. As such, we propose a novel evaluation measure, parametric norm-balls, by directly perturbing physical parameters that underly image formation. One enabling contribution we present is a physically-based differentiable renderer that allows us to propagate pixel gradients to the parametric space of lighting and geometry. Our approach enables physically-based adversarial attacks, and our differentiable renderer leverages models from the interactive rendering literature to balance the performance and accuracy trade-offs necessary for a memory-efficient and scalable adversarial data augmentation workflow.

READ FULL TEXT
research
08/08/2018

Adversarial Geometry and Lighting using a Differentiable Renderer

Many machine learning classifiers are vulnerable to adversarial attacks,...
research
11/20/2017

Adversarial Attacks Beyond the Image Space

Generating adversarial examples is an intriguing problem and an importan...
research
06/06/2019

Should Adversarial Attacks Use Pixel p-Norm?

Adversarial attacks aim to confound machine learning systems, while rema...
research
08/03/2019

Learning to Predict 3D Objects with an Interpolation-based Differentiable Renderer

Many machine learning models operate on images, but ignore the fact that...
research
01/26/2018

Deflecting Adversarial Attacks with Pixel Deflection

CNNs are poised to become integral parts of many critical systems. Despi...
research
10/07/2021

One Thing to Fool them All: Generating Interpretable, Universal, and Physically-Realizable Adversarial Features

It is well understood that modern deep networks are vulnerable to advers...
research
02/28/2023

PixHt-Lab: Pixel Height Based Light Effect Generation for Image Compositing

Lighting effects such as shadows or reflections are key in making synthe...

Please sign up or login with your details

Forgot password? Click here to reset