The Importance of Image Interpretation: Patterns of Semantic Misclassification in Real-World Adversarial Images

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Adversarial images are created with the intention of causing an image classifier to produce a misclassification. In this paper, we propose that adversarial images should be evaluated based on semantic mismatch, rather than label mismatch, as used in current work. In other words, we propose that an image of a “mug” would be considered adversarial if classified as “turnip”, but not as “cup”, as current systems would assume. Our novel idea of taking semantic misclassification into account in the evaluation of adversarial images offers two benefits. First, it is a more realistic conceptualization of what makes an image adversarial, which is important in order to fully understand the implications of adversarial images for security and privacy. Second, it makes it possible to evaluate the transferability of adversarial images to a real-world classifier, without requiring the classifier’s label set to have been available during the creation of the images. The paper carries out an evaluation of a transfer attack on a real-world image classifier that is made possible by our semantic misclassification approach. The attack reveals patterns in the semantics of adversarial misclassifications that could not be investigated using conventional label mismatch.

Original languageEnglish
Title of host publicationMultiMedia Modeling - 29th International Conference, MMM 2023, Proceedings
EditorsDuc-Tien Dang-Nguyen, Cathal Gurrin, Alan F. Smeaton, Martha Larson, Stevan Rudinac, Minh-Son Dao, Christoph Trattner, Phoebe Chen
PublisherSpringer Science and Business Media Deutschland GmbH
Pages718-725
Number of pages8
ISBN (Print)9783031278174
DOIs
StatePublished - 2023
Externally publishedYes
Event29th International Conference on MultiMedia Modeling, MMM 2023 - Bergen, Norway
Duration: 9 Jan 202312 Jan 2023

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume13834 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference29th International Conference on MultiMedia Modeling, MMM 2023
Country/TerritoryNorway
CityBergen
Period9/01/2312/01/23

Keywords

  • Adversarial images
  • Image semantics
  • Real-world systems

Fingerprint

Dive into the research topics of 'The Importance of Image Interpretation: Patterns of Semantic Misclassification in Real-World Adversarial Images'. Together they form a unique fingerprint.

Cite this