Pith. sign in

REVIEW 1 cited by

Demiguise Attack: Crafting Invisible Semantic Adversarial Perturbations with Perceptual Similarity

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2107.01396 v1 pith:JK2KLVZG submitted 2021-07-03 cs.CV cs.AI

classification cs.CVcs.AI
keywords adversarialperturbationsexamplesattacksperceptualsimilarityattackcrafting
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
abstract

Deep neural networks (DNNs) have been found to be vulnerable to adversarial examples. Adversarial examples are malicious images with visually imperceptible perturbations. While these carefully crafted perturbations restricted with tight $\Lp$ norm bounds are small, they are still easily perceivable by humans. These perturbations also have limited success rates when attacking black-box models or models with defenses like noise reduction filters. To solve these problems, we propose Demiguise Attack, crafting ``unrestricted'' perturbations with Perceptual Similarity. Specifically, we can create powerful and photorealistic adversarial examples by manipulating semantic information based on Perceptual Similarity. Adversarial examples we generate are friendly to the human visual system (HVS), although the perturbations are of large magnitudes. We extend widely-used attacks with our approach, enhancing adversarial effectiveness impressively while contributing to imperceptibility. Extensive experiments show that the proposed method not only outperforms various state-of-the-art attacks in terms of fooling rate, transferability, and robustness against defenses but can also improve attacks effectively. In addition, we also notice that our implementation can simulate illumination and contrast changes that occur in real-world scenarios, which will contribute to exposing the blind spots of DNNs.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Nearly Zero-Cost Protection Against Mimicry by Personalized Diffusion Models

    cs.CV 2024-12 conditional novelty 6.0 of 10

    A pre-trained mixture of perturbations makes diffusion-model image protection nearly instant while keeping comparable disruption of style mimicry.

Pith tools