返回
Lambertian-based adversarial attacks on deep-learning-based underwater side-scan sonar image classification
DOI:10.1016/j.patcog.2023.109363.png)
摘要
En 中文
Deep convolutional neural networks (CNNs) are extensively applied to the classification tasks for Side -scan sonar (SSS) images. However, state-of-the-art neural networks are prone to be confused by adver-sarial attacks that generate a tiny modification of the images, threatening the security of SSS classifica-tion. The robustness of CNN to adversarial attacks can be improved by introducing adversarial examples through adversarial training. Practical adversarial examples are often generated from elaborate adversarial attackers. For the underwater scenario of sonar, a specially designed adversarial attack method to weaken SSS image classification can make the research community better understand the weakness of CNN in this scenario and improve the security measures in a well-directed way. Thus, exploring adversarial attack methods for SSS image classification is essential. Nevertheless, the existing adversarial attack methods are designed for optical images, reflecting no physical characteristics of sonar images. To fill this gap and investigate the adversarial attack related to real-world conditions, in this paper, we propose an adversar-ial attack method named Lambertian Adversarial Sonar Attack (LASA). It initially leverages the Lambertian model to simulate the formation of the SSS image, factoring the image to three parameters, then updates the parameters on the direction of gradients by the chain rule. Finally, the parameters regenerate the adversarial example to fool the classifier. To validate the performance of LASA, we constructed a diver-sified SSS image dataset containing three categories. On our dataset, LASA reduces the Top-1 accuracy of a well-trained ResNet-101 to 7 . 31% +/- 0 . 21 (one-shot version) and 0.00% (iterative version), the success rate of targeted attack reaches 97 . 03 +/- 2 . 24 , far beyond the performance of the existing state-of-the-art adversarial attack methods. Meanwhile, we show that the adversarial training using examples generated from LASA makes the classifier more robust. We expect that our methods can be applied as a bench-mark of adversarial attacks on SSS images, motivating future research to design novel neural networks or defensive methods to resist real-world adversarial attacks on SSS images. (c) 2023 Elsevier Ltd. All rights reserved.
Keyword:
Adversarial attack
Classification
Side-scan sonar
Lambertian model
期刊
IF:
7.6
论文数:
1.3W
被引数:
4.5W
机构
引用论文
Advances in Adversarial Attacks and Defenses in Computer Vision: A Survey计算机视觉中对抗性攻击和防御的进展: 综述
IEEE ACCESS
IF3.6
Threat of Adversarial Attacks on Deep Learning in Computer Vision: A Survey计算机视觉中对抗性攻击对深度学习的威胁: 一项调查
IEEE ACCESS
IF3.6
Frequency domain regularization for iterative adversarial attacks迭代对抗攻击的频域正则化
PATTERN RECOGNITION
IF7.6

