ICASSP 2022accepted0 citations

In Pursuit of Preserving the Fidelity of Adversarial Images

Joseph Clements, Yingjie Lao

Abstract

Adversarial examples have emerged as a severe concern for the security of neural networks. However, the ℓ <inf xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">p</inf> -distances, typically used as a similarity constraint, often fail to capture human perceived similarity. Under challenging scenarios, such as attacking a defended model, this discrepancy leads to the severe degradation of image fidelity. In this paper, we find adversarial examples that better match the natural distribution of the input domain by integrating signal processing techniques into the attack framework, dynamically altering the allowed perturbation with a Rule Adjustable Distance (RAD <inf xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">ρ</inf> ). The framework allows us to easily in-corporate structural similarity, Otsu’s method, or variance filtering to increase the fidelity of adversarial images while still adhering to an ℓ <inf xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">p</inf> -bound.

BibTeX
@inproceedings{icassp2022_inpursuitofprese,
  title = {In Pursuit of Preserving the Fidelity of Adversarial Images},
  author = {Joseph Clements and Yingjie Lao},
  booktitle = {ICASSP 2022},
  year = {2022}
}
In Pursuit of Preserving the Fidelity of Adversarial Images · ICASSP 2022