Published June 6, 2022 | Version v1

A boostershot for transferable physically realizable adversarial examples

  • 1. imec-DistriNet, KU Leuven

Description

Abstract—Adversarial perturbations are claimed to enlarge the attack surface of machine learning models. However, as the most prominent attack methodologies require unrealistically strong adversaries, they are hardly used in attacks against realworld systems. In this paper, we alleviate the constraints on the threat model and attack a face recognition system with physically realizable perturbations in a black-box scenario, provided a single attack attempt. As such, we are forced to rely on more pragmatic, but less effective, attack methods that leverage transferability – adversarial perturbations successful on known models tend to also work on unknown ones.We overcome the poor attack success rate of transferability by using adversarially trained surrogate models.

Notes

The poster was accepted at the 7th IEEE European Symposium on Security and Privacy (Euro S&P 2022) and presented in the poster session. Original poster: https://ieeeeurosp.github.io/2022/posters/

Files

eurosp22posters-final4-1-3.pdf

Files (396.8 kB)

Name Size Download all
md5:b8e9ed791ea6b8d1a8836d6469f79b75
396.8 kB Preview Download

Additional details

Related works

Is part of
Poster: 10.5281/zenodo.7068698 (DOI)