Pith. sign in

REVIEW 2 cited by

Adversarial Examples for Semantic Segmentation and Object Detection

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1703.08603 v3 pith:LAUMCFFW submitted 2017-03-24 cs.CV

classification cs.CV
keywords adversarialdetectionsegmentationexamplesnetworksperturbationsdifferentobject
verification ladder T0 review T1 audit T2 compute T3 formal

Signed reviews

No signed human review yet.

0 comments
read the original abstract

It has been well demonstrated that adversarial examples, i.e., natural images with visually imperceptible perturbations added, generally exist for deep networks to fail on image classification. In this paper, we extend adversarial examples to semantic segmentation and object detection which are much more difficult. Our observation is that both segmentation and detection are based on classifying multiple targets on an image (e.g., the basic target is a pixel or a receptive field in segmentation, and an object proposal in detection), which inspires us to optimize a loss function over a set of pixels/proposals for generating adversarial perturbations. Based on this idea, we propose a novel algorithm named Dense Adversary Generation (DAG), which generates a large family of adversarial examples, and applies to a wide range of state-of-the-art deep networks for segmentation and detection. We also find that the adversarial perturbations can be transferred across networks with different training data, based on different architectures, and even for different recognition tasks. In particular, the transferability across networks with the same architecture is more significant than in other cases. Besides, summing up heterogeneous perturbations often leads to better transfer performance, which provides an effective method of black-box adversarial attack.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. AdvHat: Real-world adversarial attack on ArcFace Face ID system

    cs.CV 2019-08 conditional novelty 6.0 of 10

    A printable hat sticker, optimized with an off-plane bending transformation, reduces ArcFace face-ID similarity enough to dodge recognition in real-world photos.

  2. Verification of Neural Network Control Policy Under Persistent Adversarial Perturbation

    cs.LG 2019-08 conditional novelty 6.0 of 10

    A sufficient-condition algorithm certifies boundedness of a closed-loop neural-network control system under l-infinity-bounded persistent adversarial perturbation, without requiring Lipschitz continuity of the policy.

Pith tools