A boostershot for transferable physically realizable adversarial examples
Authors/Creators
- 1. imec-DistriNet, KU Leuven
Description
Abstract—Adversarial perturbations are claimed to enlarge the attack surface of machine learning models. However, as the most prominent attack methodologies require unrealistically strong adversaries, they are hardly used in attacks against realworld systems. In this paper, we alleviate the constraints on the threat model and attack a face recognition system with physically realizable perturbations in a black-box scenario, provided a single attack attempt. As such, we are forced to rely on more pragmatic, but less effective, attack methods that leverage transferability – adversarial perturbations successful on known models tend to also work on unknown ones.We overcome the poor attack success rate of transferability by using adversarially trained surrogate models.
Notes
Files
eurosp22posters-final4-1-3.pdf
Files
(396.8 kB)
| Name | Size | Download all |
|---|---|---|
|
md5:b8e9ed791ea6b8d1a8836d6469f79b75
|
396.8 kB | Preview Download |
Additional details
Related works
- Is part of
- Poster: 10.5281/zenodo.7068698 (DOI)