Article (Scientific journals)
A strategy creating high-resolution adversarial images against convolutional neural networks and a feasibility study on 10 CNNs
LEPREVOST, Franck; TOPAL, Ali Osman; Avdusinovic, Elmir et al.
2022In Journal of Information and Telecommunication, 7 (1), p. 89-119
Peer Reviewed verified by ORBi
 

Files


Full Text
A strategy creating high resolution adversarial images against convolutional neural networks and a feasibility study on 10 CNNs.pdf
Publisher postprint (6.7 MB)
Download

All documents in ORBilu are protected by a user license.

Send to



Details



Keywords :
Black-box attack; Convolutional Neural Network; Evolutionary Algorithm; high-resolution adversarial image
Abstract :
[en] To perform image recognition, Convolutional Neural Networks (CNNs) assess any image by first resizing it to its input size. In particular, high-resolution images are scaled down, say to 224×244 for CNNs trained on ImageNet. So far, existing attacks, aiming at creating an adversarial image that a CNN would misclassify while a human would not notice any difference between the modified and unmodified images, proceed by creating adversarial noise in the 224×244 resized domain and not in the high-resolution domain. The complexity of directly attacking high-resolution images leads to challenges in terms of speed, adversity and visual quality, making these attacks infeasible in practice. We design an indirect attack strategy that lifts to the high-resolution domain any existing attack that works efficiently in the CNN's input size domain. Adversarial noise created via this method is of the same size as the original image. We apply this approach to 10 state-of-the-art CNNs trained on ImageNet, with an evolutionary algorithm-based attack. Our method succeeded in 900 out of 1000 trials to create such adversarial images, that CNNs classify with probability ≥0.55 in the adversarial category. Our indirect attack is the first effective method at creating adversarial images in the high-resolution domain.
Research center :
ULHPC - University of Luxembourg: High Performance Computing
Disciplines :
Computer science
Author, co-author :
LEPREVOST, Franck ;  University of Luxembourg > Faculty of Science, Technology and Medicine (FSTM) > Department of Computer Science (DCS)
TOPAL, Ali Osman ;  University of Luxembourg > Faculty of Science, Technology and Medicine (FSTM) > Department of Computer Science (DCS)
Avdusinovic, Elmir
CHITIC, Ioana Raluca ;  University of Luxembourg > Faculty of Science, Technology and Medicine (FSTM) > Department of Computer Science (DCS)
External co-authors :
no
Language :
English
Title :
A strategy creating high-resolution adversarial images against convolutional neural networks and a feasibility study on 10 CNNs
Publication date :
22 October 2022
Journal title :
Journal of Information and Telecommunication
ISSN :
2475-1839
eISSN :
2475-1847
Publisher :
Taylor & Francis Group, United Kingdom
Volume :
7
Issue :
1
Pages :
89-119
Peer reviewed :
Peer Reviewed verified by ORBi
Focus Area :
Computational Sciences
Available on ORBilu :
since 29 May 2023

Statistics


Number of views
82 (4 by Unilu)
Number of downloads
20 (2 by Unilu)

Scopus citations®
 
1
Scopus citations®
without self-citations
0
OpenCitations
 
0
OpenAlex citations
 
2
WoS citations
 
2

publications
0
supporting
0
mentioning
0
contrasting
0
Smart Citations
0
0
0
0
Citing PublicationsSupportingMentioningContrasting
View Citations

See how this article has been cited at scite.ai

scite shows how a scientific paper has been cited by providing the context of the citation, a classification describing whether it supports, mentions, or contrasts the cited claim, and a label indicating in which section the citation was made.

Bibliography


Similar publications



Sorry the service is unavailable at the moment. Please try again later.
Contact ORBilu