ImageNet-Patch: A Dataset for Benchmarking Machine Learning Robustness against Adversarial Patches

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Pintor, Maura, Angioni, Daniele, Sotgiu, Angelo, Demetrio, Luca, Demontis, Ambra, Biggio, Battista, Roli, Fabio
Natura: Preprint
Pubblicazione: 2022
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866913649815191552
author Pintor, Maura
Angioni, Daniele
Sotgiu, Angelo
Demetrio, Luca
Demontis, Ambra
Biggio, Battista
Roli, Fabio
author_facet Pintor, Maura
Angioni, Daniele
Sotgiu, Angelo
Demetrio, Luca
Demontis, Ambra
Biggio, Battista
Roli, Fabio
contents Adversarial patches are optimized contiguous pixel blocks in an input image that cause a machine-learning model to misclassify it. However, their optimization is computationally demanding, and requires careful hyperparameter tuning, potentially leading to suboptimal robustness evaluations. To overcome these issues, we propose ImageNet-Patch, a dataset to benchmark machine-learning models against adversarial patches. It consists of a set of patches, optimized to generalize across different models, and readily applicable to ImageNet data after preprocessing them with affine transformations. This process enables an approximate yet faster robustness evaluation, leveraging the transferability of adversarial perturbations. We showcase the usefulness of this dataset by testing the effectiveness of the computed patches against 127 models. We conclude by discussing how our dataset could be used as a benchmark for robustness, and how our methodology can be generalized to other domains. We open source our dataset and evaluation code at https://github.com/pralab/ImageNet-Patch.
format Preprint
id arxiv_https___arxiv_org_abs_2203_04412
institution arXiv
publishDate 2022
record_format arxiv
spellingShingle ImageNet-Patch: A Dataset for Benchmarking Machine Learning Robustness against Adversarial Patches
Pintor, Maura
Angioni, Daniele
Sotgiu, Angelo
Demetrio, Luca
Demontis, Ambra
Biggio, Battista
Roli, Fabio
Cryptography and Security
Computer Vision and Pattern Recognition
Machine Learning
Adversarial patches are optimized contiguous pixel blocks in an input image that cause a machine-learning model to misclassify it. However, their optimization is computationally demanding, and requires careful hyperparameter tuning, potentially leading to suboptimal robustness evaluations. To overcome these issues, we propose ImageNet-Patch, a dataset to benchmark machine-learning models against adversarial patches. It consists of a set of patches, optimized to generalize across different models, and readily applicable to ImageNet data after preprocessing them with affine transformations. This process enables an approximate yet faster robustness evaluation, leveraging the transferability of adversarial perturbations. We showcase the usefulness of this dataset by testing the effectiveness of the computed patches against 127 models. We conclude by discussing how our dataset could be used as a benchmark for robustness, and how our methodology can be generalized to other domains. We open source our dataset and evaluation code at https://github.com/pralab/ImageNet-Patch.
title ImageNet-Patch: A Dataset for Benchmarking Machine Learning Robustness against Adversarial Patches
topic Cryptography and Security
Computer Vision and Pattern Recognition
Machine Learning
url https://arxiv.org/abs/2203.04412