Article (Scientific journals)
A strategy creating high-resolution adversarial images against convolutional neural networks and a feasibility study on 10 CNNs
Leprevost, Franck; Topal, Ali Osman; Avdusinovic, Elmir et al.
2022In Journal of Information and Telecommunication, 7 (1), p. 89-119
Peer Reviewed verified by ORBi
 

Files


Full Text
A strategy creating high resolution adversarial images against convolutional neural networks and a feasibility study on 10 CNNs.pdf
Publisher postprint (6.7 MB)
Download

All documents in ORBilu are protected by a user license.

Send to



Details



Keywords :
Black-box attack; Convolutional Neural Network; Evolutionary Algorithm; high-resolution adversarial image
Abstract :
[en] To perform image recognition, Convolutional Neural Networks (CNNs) assess any image by first resizing it to its input size. In particular, high-resolution images are scaled down, say to 224×244 for CNNs trained on ImageNet. So far, existing attacks, aiming at creating an adversarial image that a CNN would misclassify while a human would not notice any difference between the modified and unmodified images, proceed by creating adversarial noise in the 224×244 resized domain and not in the high-resolution domain. The complexity of directly attacking high-resolution images leads to challenges in terms of speed, adversity and visual quality, making these attacks infeasible in practice. We design an indirect attack strategy that lifts to the high-resolution domain any existing attack that works efficiently in the CNN's input size domain. Adversarial noise created via this method is of the same size as the original image. We apply this approach to 10 state-of-the-art CNNs trained on ImageNet, with an evolutionary algorithm-based attack. Our method succeeded in 900 out of 1000 trials to create such adversarial images, that CNNs classify with probability ≥0.55 in the adversarial category. Our indirect attack is the first effective method at creating adversarial images in the high-resolution domain.
Research center :
ULHPC - University of Luxembourg: High Performance Computing
Disciplines :
Computer science
Author, co-author :
Leprevost, Franck ;  University of Luxembourg > Faculty of Science, Technology and Medicine (FSTM) > Department of Computer Science (DCS)
Topal, Ali Osman ;  University of Luxembourg > Faculty of Science, Technology and Medicine (FSTM) > Department of Computer Science (DCS)
Avdusinovic, Elmir
Chitic, Ioana Raluca ;  University of Luxembourg > Faculty of Science, Technology and Medicine (FSTM) > Department of Computer Science (DCS)
External co-authors :
no
Language :
English
Title :
A strategy creating high-resolution adversarial images against convolutional neural networks and a feasibility study on 10 CNNs
Publication date :
22 October 2022
Journal title :
Journal of Information and Telecommunication
ISSN :
2475-1847
Publisher :
Taylor & Francis Group, United Kingdom
Volume :
7
Issue :
1
Pages :
89-119
Peer reviewed :
Peer Reviewed verified by ORBi
Focus Area :
Computational Sciences
Available on ORBilu :
since 29 May 2023

Statistics


Number of views
51 (1 by Unilu)
Number of downloads
11 (1 by Unilu)

Scopus citations®
 
0
Scopus citations®
without self-citations
0
OpenCitations
 
0
WoS citations
 
1

Bibliography


Similar publications



Contact ORBilu