论文标题

颜色和边缘感的对抗图像扰动

Color and Edge-Aware Adversarial Image Perturbations

论文作者

Bassett, Robert, Graves, Mitchell, Reilly, Patrick

论文摘要

图像的对抗性扰动,其中故意修改源图像,目的是导致分类器错误地分类图像,它为图像分类器的鲁棒性提供了重要的见解。在这项工作中,我们开发了两种构建对抗性扰动的新方法,这两种方法都是通过最小化人类检测扰动和源图像之间变化的能力而进行的。第一个是边缘感知方法,减少了在图像的平滑区域中允许更容易检测到变化的光滑区域中允许的扰动幅度。我们的第二种方法是色彩吸引的方法,在颜色空间中执行扰动,该颜色空间准确地捕获了人类区分颜色差异的能力,从而减少了感知的变化。也可以同时实现有色人种和边缘感知方法,从而导致图像扰动,这既是人类的颜色感知和对均质区域变化的敏感性。由于许多图像扰动技术存在边缘感知和色彩吸引力的修改,因此我们还专注于计算以证明其在更复杂的扰动方案中使用的潜力。我们从经验上证明,我们认为有效引起错误分类的色素感知和边缘感知的扰动对人类感知的区分较差,并且像最有效的图像扰动技术一样易于计算。代码和演示可在https://github.com/rbassett3/color-and-ge-ware-ware-perturbation

Adversarial perturbation of images, in which a source image is deliberately modified with the intent of causing a classifier to misclassify the image, provides important insight into the robustness of image classifiers. In this work we develop two new methods for constructing adversarial perturbations, both of which are motivated by minimizing human ability to detect changes between the perturbed and source image. The first of these, the Edge-Aware method, reduces the magnitude of perturbations permitted in smooth regions of an image where changes are more easily detected. Our second method, the Color-Aware method, performs the perturbation in a color space which accurately captures human ability to distinguish differences in colors, thus reducing the perceived change. The Color-Aware and Edge-Aware methods can also be implemented simultaneously, resulting in image perturbations which account for both human color perception and sensitivity to changes in homogeneous regions. Because Edge-Aware and Color-Aware modifications exist for many image perturbations techniques, we also focus on computation to demonstrate their potential for use within more complex perturbation schemes. We empirically demonstrate that the Color-Aware and Edge-Aware perturbations we consider effectively cause misclassification, are less distinguishable to human perception, and are as easy to compute as the most efficient image perturbation techniques. Code and demo available at https://github.com/rbassett3/Color-and-Edge-Aware-Perturbations

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源