Pith. sign in

REVIEW 1 cited by

Instruct2Attack: Language-Guided Semantic Adversarial Attacks

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2311.15551 v1 pith:ZDDSKG56 submitted 2023-11-27 cs.CV cs.AIcs.CRcs.LGeess.IV

classification cs.CVcs.AIcs.CRcs.LGeess.IV
keywords adversarialsemanticattackattacksdiffusiondiversegeneratesinstruct2attack
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

We propose Instruct2Attack (I2A), a language-guided semantic attack that generates semantically meaningful perturbations according to free-form language instructions. We make use of state-of-the-art latent diffusion models, where we adversarially guide the reverse diffusion process to search for an adversarial latent code conditioned on the input image and text instruction. Compared to existing noise-based and semantic attacks, I2A generates more natural and diverse adversarial examples while providing better controllability and interpretability. We further automate the attack process with GPT-4 to generate diverse image-specific text instructions. We show that I2A can successfully break state-of-the-art deep neural networks even under strong adversarial defenses, and demonstrate great transferability among a variety of network architectures.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Prompt2Perturb (P2P): Text-Guided Diffusion-Based Adversarial Attacks on Breast Ultrasound Images

    cs.CV 2024-12 conditional novelty 4.0 of 10

    Prompt2Perturb finds Stable Diffusion text embeddings that turn breast ultrasound images into adversarial examples that are natural-looking and mislead classifiers.

Pith tools