论文标题

所有交易的千斤顶,无主任:通过透明的补丁攻击解决分配变化和掩盖性

Jacks of All Trades, Masters Of None: Addressing Distributional Shift and Obtrusiveness via Transparent Patch Attacks

论文作者

Fendley, Neil, Lennon, Max, Wang, I-Jeng, Burlina, Philippe, Drenkow, Nathan

论文摘要

我们专注于有效的对抗斑块攻击的发展,并首次通过新颖的半透明斑块的设计共同解决了攻击成功和情绪的拮抗目标。这项工作是由于我们追求对几何转换的贴片攻击鲁棒性进行系统的性能分析而进行的。具体而言,我们首先阐明a)基于补丁攻击成功的关键因素,b)当训练和测试/部署之间的分布转移的影响是在对变换(EOT)形式主义的期望下。通过将我们的分析重点放在三个主要的转换类别(旋转,规模和位置)上,我们的发现为有效的贴片攻击设计提供了可量化的见解,并证明了规模的所有因素,都显着影响了补丁攻击的成功。从这些发现中工作,我们专注于解决如何克服实际物理环境中攻击的主要规模局限性:即大斑块的讨厌。我们的策略是转向不规则形状的半透明部分斑块的新设计,我们通过新的优化过程构建,该过程共同解决了降低混淆性和最大化有效性的拮抗目标。我们的研究 - 我们希望 - 将有助于鼓励社区更多地关注贴片攻击的问题,规模和成功的问题。

We focus on the development of effective adversarial patch attacks and -- for the first time -- jointly address the antagonistic objectives of attack success and obtrusiveness via the design of novel semi-transparent patches. This work is motivated by our pursuit of a systematic performance analysis of patch attack robustness with regard to geometric transformations. Specifically, we first elucidate a) key factors underpinning patch attack success and b) the impact of distributional shift between training and testing/deployment when cast under the Expectation over Transformation (EoT) formalism. By focusing our analysis on three principal classes of transformations (rotation, scale, and location), our findings provide quantifiable insights into the design of effective patch attacks and demonstrate that scale, among all factors, significantly impacts patch attack success. Working from these findings, we then focus on addressing how to overcome the principal limitations of scale for the deployment of attacks in real physical settings: namely the obtrusiveness of large patches. Our strategy is to turn to the novel design of irregularly-shaped, semi-transparent partial patches which we construct via a new optimization process that jointly addresses the antagonistic goals of mitigating obtrusiveness and maximizing effectiveness. Our study -- we hope -- will help encourage more focus in the community on the issues of obtrusiveness, scale, and success in patch attacks.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源