Dual adversarial attacks : Fooling humans and classifiers

dc.contributor.authorSchneider, Johannes
dc.contributor.authorApruzzese, Giovanni
dc.contributor.departmentDepartment of Computer Science
dc.date.accessioned2026-09-25T15:08:01Z
dc.date.available2026-09-25T15:08:01Z
dc.date.issued2023-06
dc.descriptionPublisher Copyright: © 2023 The Author(s)en
dc.description.abstractAdversarial samples mostly aim at fooling machine learning (ML) models. They often involve minor pixel-based perturbations that are imperceptible to human observers. In this work, adversarial samples should fool both humans and ML models, which is important in two-stage decision processes. We perform changes on a higher abstraction level so that a target sample exhibits properties of a desired sample. Technically, we contribute by deriving a regularization scheme for autoencoders incorporating a classifier loss for smoothly interpolating between wildly different samples. The realism and effectiveness of generated samples are confirmed with a user study and other evaluations. Our experiments consider neural networks of four architectures, assessed on MNIST, FashionMNIST, QuickDraw and CIFAR-10. Results show that our scheme leads to superior performance compared to existing interpolation techniques: on average, other methods have an 11% higher failure rate when producing a sample that is of any of two interpolated classes. Furthermore, our attacks work in both white- and black-box settings.en
dc.description.versionPeer revieweden
dc.format.extent5574403
dc.format.extent
dc.identifier.citationSchneider, J & Apruzzese, G 2023, 'Dual adversarial attacks : Fooling humans and classifiers', Journal of Information Security and Applications, vol. 75, 103502. https://doi.org/10.1016/j.jisa.2023.103502en
dc.identifier.doi10.1016/j.jisa.2023.103502
dc.identifier.issn2214-2134
dc.identifier.other250865697
dc.identifier.other50e179de-b846-4bc5-b940-2ea665adba12
dc.identifier.other85154548735
dc.identifier.urihttps://hdl.handle.net/20.500.11815/8413
dc.language.isoen
dc.relation.ispartofseriesJournal of Information Security and Applications; 75()en
dc.relation.urlhttps://www.scopus.com/pages/publications/85154548735en
dc.rightsinfo:eu-repo/semantics/openAccessen
dc.subjectAdversarial attacksen
dc.subjectComputer visionen
dc.subjectDeep learningen
dc.subjectDual attacksen
dc.subjectSoftwareen
dc.subjectSafety, Risk, Reliability and Qualityen
dc.subjectComputer Networks and Communicationsen
dc.titleDual adversarial attacks : Fooling humans and classifiersen
dc.type/dk/atira/pure/researchoutput/researchoutputtypes/contributiontojournal/articleen

Skrár

Original bundle

Niðurstöður 1 - 1 af 1
Nafn:
1-s2.0-S2214212623000868-main.pdf
Stærð:
5.32 MB
Snið:
Adobe Portable Document Format