Double Targeted Universal Adversarial Perturbations
Philipp Benz (KAIST)*, Chaoning Zhang (KAIST), Tooba Imtiaz (KAIST), In So Kweon (KAIST)
Keywords: Deep Learning for Computer Vision
Abstract:
Despite their impressive performance, deep neural networks (DNNs) are widely known to be vulnerable to adversarial attacks, which makes it challenging for them to be deployed in security-sensitive applications, such as autonomous driving. Image-dependent perturbations can fool a network for one specific image, while universal adversarial perturbations are capable of fooling a network for samples from all classes without selection. We introduce a double targeted universal adversarial perturbations (DT-UAPs) to bridge the gap between the instance-discriminative image-dependent perturbations and the generic universal perturbations. This universal perturbation attacks one targeted source class to sink class, while having a limited adversarial effect on other non-targeted source classes, for avoiding raising suspicions. Targeting the source and sink class simultaneously, we term it double targeted attack (DTA). This provides an attacker with the freedom to perform precise attacks on a DNN model while raising little suspicion. We show the effectiveness of the proposed DTA algorithm on a wide range of datasets and also demonstrate its potential as a physical attack.
SlidesLive
Similar Papers
Localize to Classify and Classify to Localize: Mutual Guidance in Object Detection
Heng Zhang (Univ Rennes 1)*, Elisa Fromont (Université Rennes 1, IRISA/INRIA rba), Sébastien Lefèvre (Université de Bretagne Sud / IRISA), Bruno Avignon (Atermes)

Knowledge Transfer Graph for Deep Collaborative Learning
Soma Minami (Chubu university)*, Tsubasa Hirakawa (Chubu University), Takayoshi Yamashita (Chubu University), Hironobu Fujiyoshi (Chubu University)

Understanding Motion in Sign Language: A New Structured Translation Dataset
Jefferson Rodriguez (UIS), Juan Chacon (UIS), Edgar Rangel (UIS), Luis Guayacan (UIS), Claudia Hernandez (UIS), Luisa Hernandez (UIS), Fabio Martinez (UIS )*
