Skip to main navigation Skip to search Skip to main content

Towards Large Yet Imperceptible Adversarial Image Perturbations with Perceptual Color Distance

Research output: Contribution to journalConference articlepeer-review

153 Scopus citations

Abstract

The success of image perturbations that are designed to fool image classifier is assessed in terms of both adversarial effect and visual imperceptibility. The conventional assumption on imperceptibility is that perturbations should strive for tight Lp-norm bounds in RGB space. In this work, we drop this assumption by pursuing an approach that exploits human color perception, and more specifically, minimizing perturbation size with respect to perceptual color distance. Our first approach, Perceptual Color distance CW (PerC-CW), extends the widely-used CW approach and produces larger RGB perturbations. PerC-CW is able to maintain adversarial strength, while contributing to imperceptibility. Our second approach, Perceptual Color distance Alternating Loss (PerC-AL), achieves the same outcome, but does so more efficiently by alternating between the classification loss and perceptual color difference when updating perturbations. Experimental evaluation shows PerC approaches outperform conventional Lp approaches in terms of robustness and transferability, and also demonstrates that the PerC distance can provide added value on top of existing structure-based methods to creating image perturbations.

Original languageEnglish
Article number9157804
Pages (from-to)1036-1045
Number of pages10
JournalProceedings of the IEEE Computer Society Conference on Computer Vision and Pattern Recognition
DOIs
StatePublished - 2020
Externally publishedYes
Event2020 IEEE/CVF Conference on Computer Vision and Pattern Recognition, CVPR 2020 - Virtual, Online, United States
Duration: 14 Jun 202019 Jun 2020

Fingerprint

Dive into the research topics of 'Towards Large Yet Imperceptible Adversarial Image Perturbations with Perceptual Color Distance'. Together they form a unique fingerprint.

Cite this