Uncertainty-weighted Loss Functions for Improved Adversarial Attacks on Semantic Segmentation

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Maag, Kira, Fischer, Asja
Format: Preprint
Published: 2023
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909986883371008
author Maag, Kira
Fischer, Asja
author_facet Maag, Kira
Fischer, Asja
contents State-of-the-art deep neural networks have been shown to be extremely powerful in a variety of perceptual tasks like semantic segmentation. However, these networks are vulnerable to adversarial perturbations of the input which are imperceptible for humans but lead to incorrect predictions. Treating image segmentation as a sum of pixel-wise classifications, adversarial attacks developed for classification models were shown to be applicable to segmentation models as well. In this work, we present simple uncertainty-based weighting schemes for the loss functions of such attacks that (i) put higher weights on pixel classifications which can more easily perturbed and (ii) zero-out the pixel-wise losses corresponding to those pixels that are already confidently misclassified. The weighting schemes can be easily integrated into the loss function of a range of well-known adversarial attackers with minimal additional computational overhead, but lead to significant improved perturbation performance, as we demonstrate in our empirical analysis on several datasets and models.
format Preprint
id arxiv_https___arxiv_org_abs_2310_17436
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Uncertainty-weighted Loss Functions for Improved Adversarial Attacks on Semantic Segmentation
Maag, Kira
Fischer, Asja
Computer Vision and Pattern Recognition
State-of-the-art deep neural networks have been shown to be extremely powerful in a variety of perceptual tasks like semantic segmentation. However, these networks are vulnerable to adversarial perturbations of the input which are imperceptible for humans but lead to incorrect predictions. Treating image segmentation as a sum of pixel-wise classifications, adversarial attacks developed for classification models were shown to be applicable to segmentation models as well. In this work, we present simple uncertainty-based weighting schemes for the loss functions of such attacks that (i) put higher weights on pixel classifications which can more easily perturbed and (ii) zero-out the pixel-wise losses corresponding to those pixels that are already confidently misclassified. The weighting schemes can be easily integrated into the loss function of a range of well-known adversarial attackers with minimal additional computational overhead, but lead to significant improved perturbation performance, as we demonstrate in our empirical analysis on several datasets and models.
title Uncertainty-weighted Loss Functions for Improved Adversarial Attacks on Semantic Segmentation
topic Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2310.17436