跳到主要导航 跳到搜索 跳到主要内容

Adversarial Ranking Attack and Defense

  • Mo Zhou
  • , Zhenxing Niu
  • , Le Wang
  • , Qilin Zhang
  • , Gang Hua
  • Xi'an Jiaotong University
  • Alibaba Group Holding Ltd.
  • HERE Global B.V.
  • Wormpex AI Research

科研成果: 书/报告/会议事项章节会议稿件同行评审

32 引用 (Scopus)

摘要

Deep Neural Network (DNN) classifiers are vulnerable to adversarial attack, where an imperceptible perturbation could result in misclassification. However, the vulnerability of DNN-based image ranking systems remains under-explored. In this paper, we propose two attacks against deep ranking systems, i.e., Candidate Attack and Query Attack, that can raise or lower the rank of chosen candidates by adversarial perturbations. Specifically, the expected ranking order is first represented as a set of inequalities, and then a triplet-like objective function is designed to obtain the optimal perturbation. Conversely, a defense method is also proposed to improve the ranking system robustness, which can mitigate all the proposed attacks simultaneously. Our adversarial ranking attacks and defense are evaluated on datasets including MNIST, Fashion-MNIST, and Stanford-Online-Products. Experimental results demonstrate that a typical deep ranking system can be effectively compromised by our attacks. Meanwhile, the system robustness can be moderately improved with our defense. Furthermore, the transferable and universal properties of our adversary illustrate the possibility of realistic black-box attack.

源语言英语
主期刊名Computer Vision – ECCV 2020 - 16th European Conference, 2020, Proceedings
编辑Andrea Vedaldi, Horst Bischof, Thomas Brox, Jan-Michael Frahm
出版商Springer Science and Business Media Deutschland GmbH
781-799
页数19
ISBN(印刷版)9783030585679
DOI
出版状态已出版 - 2020
活动16th European Conference on Computer Vision, ECCV 2020 - Glasgow, 英国
期限: 23 8月 202028 8月 2020

出版系列

姓名Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
12359 LNCS
ISSN(印刷版)0302-9743
ISSN(电子版)1611-3349

会议

会议16th European Conference on Computer Vision, ECCV 2020
国家/地区英国
Glasgow
时期23/08/2028/08/20

学术指纹

探究 'Adversarial Ranking Attack and Defense' 的科研主题。它们共同构成独一无二的指纹。

引用此