ADAPTIVE WARPING NETWORK FOR TRANSFERABLE ADVERSARIAL ATTACKS
- Authors
- Son, Minji; Kwon, Myung-Joon; Kim, Hee-Seon; Byun, Junyoung; Cho, Seungju; Kim, Changick
- Issue Date
- 2022
- Publisher
- IEEE
- Keywords
- Adversarial Attacks; Transfer-based Attacks; Transferability; Input Transformation; Warping
- Citation
- 2022 IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING, ICIP, pp 3056 - 3060
- Pages
- 5
- Journal Title
- 2022 IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING, ICIP
- Start Page
- 3056
- End Page
- 3060
- URI
- https://scholarworks.bwise.kr/cau/handle/2019.sw.cau/72003
- DOI
- 10.1109/ICIP46576.2022.9897701
- ISSN
- 1522-4880
- Abstract
- Deep Neural Networks (DNNs) are extremely susceptible to adversarial examples, which are crafted by intentionally adding imperceptible perturbations to clean images. Due to potential threats of adversarial attacks in practice, black-box transfer-based attacks are carefully studied to identify the vulnerability of DNNs. Unfortunately, transfer-based attacks often fail to achieve high transferability because the adversarial examples tend to overfit the source model. Applying input transformation is one of the most effective methods to avoid such overfitting. However, most previous input transformation methods obtain limited transferability because these methods utilize fixed transformations for all images. To solve the problem, we propose an Adaptive Warping Network (AWN), which searches for appropriate warping to the individual data. Specifically, AWN optimizes the warping, which mitigates the effect of adversarial perturbations in each iteration. The adversarial examples are generated to become robust against such strong transformations. Extensive experimental results on the ImageNet dataset demonstrate that AWN outperforms the existing input transformation methods in terms of transferability.
- Files in This Item
- There are no files associated with this item.
- Appears in
Collections - ETC > 1. Journal Articles
![qrcode](https://api.qrserver.com/v1/create-qr-code/?size=55x55&data=https://scholarworks.bwise.kr/cau/handle/2019.sw.cau/72003)
Items in ScholarWorks are protected by copyright, with all rights reserved, unless otherwise indicated.