论文标题

改进的图像瓦斯堡攻击和防御

Improved Image Wasserstein Attacks and Defenses

论文作者

Hu, Edward J., Swaminathan, Adith, Salman, Hadi, Yang, Greg

论文摘要

在最近的文献中,对受$ \ ell_p $ ball界定的图像扰动的鲁棒性得到了很好的研究。但是,现实世界中的扰动很少表现出$ \ ell_p $ theat模型假设的像素独立性。最近提议的瓦斯汀(Waserstein)距离距离的威胁模型是一种有前途的替代方案,它将扰动限制在像素质量运动中。我们指出并纠正了Wasserstein威胁模型的先前定义中的缺陷,并在我们定义得出的框架下探索了更强大的攻击和防御。最后,我们讨论了当前的瓦斯汀(Wasserstein-bobust)模型在捍卫现实世界中看到的扰动方面的无能。我们的代码和训练有素的模型可在https://github.com/edwardjhu/impraved_wasserstein上找到。

Robustness against image perturbations bounded by a $\ell_p$ ball have been well-studied in recent literature. Perturbations in the real-world, however, rarely exhibit the pixel independence that $\ell_p$ threat models assume. A recently proposed Wasserstein distance-bounded threat model is a promising alternative that limits the perturbation to pixel mass movements. We point out and rectify flaws in previous definition of the Wasserstein threat model and explore stronger attacks and defenses under our better-defined framework. Lastly, we discuss the inability of current Wasserstein-robust models in defending against perturbations seen in the real world. Our code and trained models are available at https://github.com/edwardjhu/improved_wasserstein .

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源