Feature Space Targeted Attacks by Statistic Alignment

05/25/2021
by   Lianli Gao, et al.
0

By adding human-imperceptible perturbations to images, DNNs can be easily fooled. As one of the mainstream methods, feature space targeted attacks perturb images by modulating their intermediate feature maps, for the discrepancy between the intermediate source and target features is minimized. However, the current choice of pixel-wise Euclidean Distance to measure the discrepancy is questionable because it unreasonably imposes a spatial-consistency constraint on the source and target features. Intuitively, an image can be categorized as "cat" no matter the cat is on the left or right of the image. To address this issue, we propose to measure this discrepancy using statistic alignment. Specifically, we design two novel approaches called Pair-wise Alignment Attack and Global-wise Alignment Attack, which attempt to measure similarities between feature maps by high-order statistics with translation invariance. Furthermore, we systematically analyze the layer-wise transferability with varied difficulties to obtain highly reliable attacks. Extensive experiments verify the effectiveness of our proposed method, and it outperforms the state-of-the-art algorithms by a large margin. Our code is publicly available at https://github.com/yaya-cheng/PAA-GAA.

READ FULL TEXT

page 8

page 9

research
07/20/2021

DSP: Dual Soft-Paste for Unsupervised Domain Adaptive Semantic Segmentation

Unsupervised domain adaptation (UDA) for semantic segmentation aims to a...
research
03/26/2021

On Generating Transferable Targeted Perturbations

While the untargeted black-box transferability of adversarial perturbati...
research
04/29/2020

Perturbing Across the Feature Hierarchy to Improve Standard and Strict Blackbox Attack Transferability

We consider the blackbox transfer-based targeted adversarial attack thre...
research
08/05/2021

IDM: An Intermediate Domain Module for Domain Adaptive Person Re-ID

Unsupervised domain adaptive person re-identification (UDA re-ID) aims a...
research
04/27/2020

Transferable Perturbations of Deep Feature Distributions

Almost all current adversarial attacks of CNN classifiers rely on inform...
research
04/12/2022

FSOINet: Feature-Space Optimization-Inspired Network for Image Compressive Sensing

In recent years, deep learning-based image compressive sensing (ICS) met...
research
06/18/2022

Camera Adaptation for Fundus-Image-Based CVD Risk Estimation

Recent studies have validated the association between cardiovascular dis...

Please sign up or login with your details

Forgot password? Click here to reset