ImageNet-Patch: A Dataset for Benchmarking Machine Learning Robustness against Adversarial Patches
Fuente:
arXiv
Salvato in:
| Autori principali: | , , , , , , |
|---|---|
| Natura: | Preprint |
| Pubblicazione: |
2022
|
| Soggetti: | |
| Accesso online: | |
| Tags: |
Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
|
| _version_ | 1866913649815191552 |
|---|---|
| author | Pintor, Maura Angioni, Daniele Sotgiu, Angelo Demetrio, Luca Demontis, Ambra Biggio, Battista Roli, Fabio |
| author_facet | Pintor, Maura Angioni, Daniele Sotgiu, Angelo Demetrio, Luca Demontis, Ambra Biggio, Battista Roli, Fabio |
| contents | Adversarial patches are optimized contiguous pixel blocks in an input image that cause a machine-learning model to misclassify it. However, their optimization is computationally demanding, and requires careful hyperparameter tuning, potentially leading to suboptimal robustness evaluations. To overcome these issues, we propose ImageNet-Patch, a dataset to benchmark machine-learning models against adversarial patches. It consists of a set of patches, optimized to generalize across different models, and readily applicable to ImageNet data after preprocessing them with affine transformations. This process enables an approximate yet faster robustness evaluation, leveraging the transferability of adversarial perturbations. We showcase the usefulness of this dataset by testing the effectiveness of the computed patches against 127 models. We conclude by discussing how our dataset could be used as a benchmark for robustness, and how our methodology can be generalized to other domains. We open source our dataset and evaluation code at https://github.com/pralab/ImageNet-Patch. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2203_04412 |
| institution | arXiv |
| publishDate | 2022 |
| record_format | arxiv |
| spellingShingle | ImageNet-Patch: A Dataset for Benchmarking Machine Learning Robustness against Adversarial Patches Pintor, Maura Angioni, Daniele Sotgiu, Angelo Demetrio, Luca Demontis, Ambra Biggio, Battista Roli, Fabio Cryptography and Security Computer Vision and Pattern Recognition Machine Learning Adversarial patches are optimized contiguous pixel blocks in an input image that cause a machine-learning model to misclassify it. However, their optimization is computationally demanding, and requires careful hyperparameter tuning, potentially leading to suboptimal robustness evaluations. To overcome these issues, we propose ImageNet-Patch, a dataset to benchmark machine-learning models against adversarial patches. It consists of a set of patches, optimized to generalize across different models, and readily applicable to ImageNet data after preprocessing them with affine transformations. This process enables an approximate yet faster robustness evaluation, leveraging the transferability of adversarial perturbations. We showcase the usefulness of this dataset by testing the effectiveness of the computed patches against 127 models. We conclude by discussing how our dataset could be used as a benchmark for robustness, and how our methodology can be generalized to other domains. We open source our dataset and evaluation code at https://github.com/pralab/ImageNet-Patch. |
| title | ImageNet-Patch: A Dataset for Benchmarking Machine Learning Robustness against Adversarial Patches |
| topic | Cryptography and Security Computer Vision and Pattern Recognition Machine Learning |
| url | https://arxiv.org/abs/2203.04412 |