Skip to Main content Skip to Navigation
Journal articles

Smooth adversarial examples

Hanwei Zhang 1 Yannis Avrithis 1 Teddy Furon 1 Laurent Amsaleg 1
1 LinkMedia - Creating and exploiting explicit links between multimedia fragments
Inria Rennes – Bretagne Atlantique , IRISA-D6 - MEDIA ET INTERACTIONS
Abstract : This paper investigates the visual quality of the adversarial examples. Recent papers propose to smooth the perturbations to get rid of high frequency artifacts. In this work, smoothing has a different meaning as it perceptually shapes the perturbation according to the visual content of the image to be attacked. The perturbation becomes locally smooth on the flat areas of the input image, but it may be noisy on its textured areas and sharp across its edges. This operation relies on Laplacian smoothing, well-known in graph signal processing, which we integrate in the attack pipeline. We benchmark several attacks with and without smoothing under a white box scenario and evaluate their transferability. Despite the additional constraint of smoothness, our attack has the same probability of success at lower distortion.
Document type :
Journal articles
Complete list of metadata

https://hal.archives-ouvertes.fr/hal-03017171
Contributor : Teddy Furon Connect in order to contact the contributor
Submitted on : Tuesday, December 8, 2020 - 3:32:52 PM
Last modification on : Tuesday, October 19, 2021 - 11:04:41 AM
Long-term archiving on: : Tuesday, March 9, 2021 - 7:40:11 PM

File

smooth.pdf
Files produced by the author(s)

Identifiers

Citation

Hanwei Zhang, Yannis Avrithis, Teddy Furon, Laurent Amsaleg. Smooth adversarial examples. EURASIP Journal on Information Security, Hindawi/SpringerOpen, 2020, 2020 (1), ⟨10.1186/s13635-020-00112-z⟩. ⟨hal-03017171⟩

Share

Metrics

Record views

100

Files downloads

134