ICASSP 2019accepted0 citations

Adversarial Watermarking to Attack Deep Neural Networks

Gengxing Wang, Xinyuan Chen, Chang Xu

Abstract

Watermark is one of the most fundamental approaches for avoiding potential copyright infringement activities. However, whether its introduction would effect the understanding of deep learning models remains unstudied. In this work, we propose a visible adversarial attack method that transforms and places a provided watermark on the target image to interfere the classification result from an Inception V3 model, which is pretrained on ImageNet. Specifically, the watermark is adjusted iteratively on location, transparency, color, angle and size which are determined by only 9 parameters. We define two types of attack to better simulate the watermark approaches in reality, respectively the watermark is constrained in either transparency or size. Experiments show that the generated adversarial samples are not only capable of fooling the Inception V3 model with high success rates, but also transferable to other models with high confidence, such as the Rekognition developed by Amazon.

BibTeX
@inproceedings{icassp2019_adversarialwater,
  title = {Adversarial Watermarking to Attack Deep Neural Networks},
  author = {Gengxing Wang and Xinyuan Chen and Chang Xu},
  booktitle = {ICASSP 2019},
  year = {2019}
}
Adversarial Watermarking to Attack Deep Neural Networks · ICASSP 2019