跳到主要导航 跳到搜索 跳到主要内容

ARCHITECTURE-AGNOSTIC ITERATIVE BLACK-BOX CERTIFIED DEFENSE AGAINST ADVERSARIAL PATCHES

  • Di Yang
  • , Yihao Huang*
  • , Qing Guo
  • , Felix Juefei-Xu
  • , Ming Hu
  • , Yang Liu
  • , Geguang Pu
  • *此作品的通讯作者
  • East China Normal University
  • Nanyang Technological University
  • Agency for Science, Technology and Research, Singapore
  • New York University

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

The adversarial patch attack aims to fool image classifiers within a bounded, contiguous region of arbitrary changes. To address this problem in a trustworthy way, the certified patch defense methods are proposed. However, the state-of-the-art certified defenses inevitably needed to access the size of the adversarial patch, which is unreasonable and impractical in real-world attack scenarios. To improve the feasibility of the architecture-agnostic certified defense in a black-box setting, we propose a novel two-stage Iterative Black-box Certified Defense method, termed IBCD. In the first stage, it estimates the patch size in a search-based manner by evaluating the size relationship between the patch and mask with pixel masking. In the second stage, the accuracy results are calculated by the existing white-box certified defense methods with the estimated patch size. The experiments conducted on two popular model architectures and two datasets verify the effectiveness and efficiency of IBCD.

源语言英语
主期刊名2024 IEEE International Conference on Acoustics, Speech, and Signal Processing, ICASSP 2024 - Proceedings
出版商Institute of Electrical and Electronics Engineers Inc.
5985-5989
页数5
ISBN(电子版)9798350344851
DOI
出版状态已出版 - 2024
活动2024 IEEE International Conference on Acoustics, Speech, and Signal Processing, ICASSP 2024 - Seoul, 韩国
期限: 14 4月 202419 4月 2024

出版系列

姓名ICASSP, IEEE International Conference on Acoustics, Speech and Signal Processing - Proceedings
ISSN(印刷版)1520-6149

会议

会议2024 IEEE International Conference on Acoustics, Speech, and Signal Processing, ICASSP 2024
国家/地区韩国
Seoul
时期14/04/2419/04/24

指纹

探究 'ARCHITECTURE-AGNOSTIC ITERATIVE BLACK-BOX CERTIFIED DEFENSE AGAINST ADVERSARIAL PATCHES' 的科研主题。它们共同构成独一无二的指纹。

引用此