Sparse patches adversarial attacks via extrapolating point-wise information

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Nemcovsky, Yaniv, Mendelson, Avi, Baskin, Chaim
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866929603859185664
author Nemcovsky, Yaniv
Mendelson, Avi
Baskin, Chaim
author_facet Nemcovsky, Yaniv
Mendelson, Avi
Baskin, Chaim
contents Sparse and patch adversarial attacks were previously shown to be applicable in realistic settings and are considered a security risk to autonomous systems. Sparse adversarial perturbations constitute a setting in which the adversarial perturbations are limited to affecting a relatively small number of points in the input. Patch adversarial attacks denote the setting where the sparse attacks are limited to a given structure, i.e., sparse patches with a given shape and number. However, previous patch adversarial attacks do not simultaneously optimize multiple patches' locations and perturbations. This work suggests a novel approach for sparse patches adversarial attacks via point-wise trimming dense adversarial perturbations. Our approach enables simultaneous optimization of multiple sparse patches' locations and perturbations for any given number and shape. Moreover, our approach is also applicable for standard sparse adversarial attacks, where we show that it significantly improves the state-of-the-art over multiple extensive settings. A reference implementation of the proposed method and the reported experiments is provided at \url{https://github.com/yanemcovsky/SparsePatches.git}
format Preprint
id arxiv_https___arxiv_org_abs_2411_16162
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Sparse patches adversarial attacks via extrapolating point-wise information
Nemcovsky, Yaniv
Mendelson, Avi
Baskin, Chaim
Computer Vision and Pattern Recognition
Machine Learning
Sparse and patch adversarial attacks were previously shown to be applicable in realistic settings and are considered a security risk to autonomous systems. Sparse adversarial perturbations constitute a setting in which the adversarial perturbations are limited to affecting a relatively small number of points in the input. Patch adversarial attacks denote the setting where the sparse attacks are limited to a given structure, i.e., sparse patches with a given shape and number. However, previous patch adversarial attacks do not simultaneously optimize multiple patches' locations and perturbations. This work suggests a novel approach for sparse patches adversarial attacks via point-wise trimming dense adversarial perturbations. Our approach enables simultaneous optimization of multiple sparse patches' locations and perturbations for any given number and shape. Moreover, our approach is also applicable for standard sparse adversarial attacks, where we show that it significantly improves the state-of-the-art over multiple extensive settings. A reference implementation of the proposed method and the reported experiments is provided at \url{https://github.com/yanemcovsky/SparsePatches.git}
title Sparse patches adversarial attacks via extrapolating point-wise information
topic Computer Vision and Pattern Recognition
Machine Learning
url https://arxiv.org/abs/2411.16162