Dual adversarial attacks : Fooling humans and classifiers
| dc.contributor.author | Schneider, Johannes | |
| dc.contributor.author | Apruzzese, Giovanni | |
| dc.contributor.department | Department of Computer Science | |
| dc.date.accessioned | 2026-09-25T15:08:01Z | |
| dc.date.available | 2026-09-25T15:08:01Z | |
| dc.date.issued | 2023-06 | |
| dc.description | Publisher Copyright: © 2023 The Author(s) | en |
| dc.description.abstract | Adversarial samples mostly aim at fooling machine learning (ML) models. They often involve minor pixel-based perturbations that are imperceptible to human observers. In this work, adversarial samples should fool both humans and ML models, which is important in two-stage decision processes. We perform changes on a higher abstraction level so that a target sample exhibits properties of a desired sample. Technically, we contribute by deriving a regularization scheme for autoencoders incorporating a classifier loss for smoothly interpolating between wildly different samples. The realism and effectiveness of generated samples are confirmed with a user study and other evaluations. Our experiments consider neural networks of four architectures, assessed on MNIST, FashionMNIST, QuickDraw and CIFAR-10. Results show that our scheme leads to superior performance compared to existing interpolation techniques: on average, other methods have an 11% higher failure rate when producing a sample that is of any of two interpolated classes. Furthermore, our attacks work in both white- and black-box settings. | en |
| dc.description.version | Peer reviewed | en |
| dc.format.extent | 5574403 | |
| dc.format.extent | ||
| dc.identifier.citation | Schneider, J & Apruzzese, G 2023, 'Dual adversarial attacks : Fooling humans and classifiers', Journal of Information Security and Applications, vol. 75, 103502. https://doi.org/10.1016/j.jisa.2023.103502 | en |
| dc.identifier.doi | 10.1016/j.jisa.2023.103502 | |
| dc.identifier.issn | 2214-2134 | |
| dc.identifier.other | 250865697 | |
| dc.identifier.other | 50e179de-b846-4bc5-b940-2ea665adba12 | |
| dc.identifier.other | 85154548735 | |
| dc.identifier.uri | https://hdl.handle.net/20.500.11815/8413 | |
| dc.language.iso | en | |
| dc.relation.ispartofseries | Journal of Information Security and Applications; 75() | en |
| dc.relation.url | https://www.scopus.com/pages/publications/85154548735 | en |
| dc.rights | info:eu-repo/semantics/openAccess | en |
| dc.subject | Adversarial attacks | en |
| dc.subject | Computer vision | en |
| dc.subject | Deep learning | en |
| dc.subject | Dual attacks | en |
| dc.subject | Software | en |
| dc.subject | Safety, Risk, Reliability and Quality | en |
| dc.subject | Computer Networks and Communications | en |
| dc.title | Dual adversarial attacks : Fooling humans and classifiers | en |
| dc.type | /dk/atira/pure/researchoutput/researchoutputtypes/contributiontojournal/article | en |
Skrár
Original bundle
1 - 1 af 1
- Nafn:
- 1-s2.0-S2214212623000868-main.pdf
- Stærð:
- 5.32 MB
- Snið:
- Adobe Portable Document Format