arrow
返回

Lambertian-based adversarial attacks on deep-learning-based underwater side-scan sonar image classification

delete2023-06-01
delete6
PRE
AI
Q
Qixiang Ma
L
L. W. Jiang *
DOI:10.1016/j.patcog.2023.109363delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Deep convolutional neural networks (CNNs) are extensively applied to the classification tasks for Side -scan sonar (SSS) images. However, state-of-the-art neural networks are prone to be confused by adver-sarial attacks that generate a tiny modification of the images, threatening the security of SSS classifica-tion. The robustness of CNN to adversarial attacks can be improved by introducing adversarial examples through adversarial training. Practical adversarial examples are often generated from elaborate adversarial attackers. For the underwater scenario of sonar, a specially designed adversarial attack method to weaken SSS image classification can make the research community better understand the weakness of CNN in this scenario and improve the security measures in a well-directed way. Thus, exploring adversarial attack methods for SSS image classification is essential. Nevertheless, the existing adversarial attack methods are designed for optical images, reflecting no physical characteristics of sonar images. To fill this gap and investigate the adversarial attack related to real-world conditions, in this paper, we propose an adversar-ial attack method named Lambertian Adversarial Sonar Attack (LASA). It initially leverages the Lambertian model to simulate the formation of the SSS image, factoring the image to three parameters, then updates the parameters on the direction of gradients by the chain rule. Finally, the parameters regenerate the adversarial example to fool the classifier. To validate the performance of LASA, we constructed a diver-sified SSS image dataset containing three categories. On our dataset, LASA reduces the Top-1 accuracy of a well-trained ResNet-101 to 7 . 31% +/- 0 . 21 (one-shot version) and 0.00% (iterative version), the success rate of targeted attack reaches 97 . 03 +/- 2 . 24 , far beyond the performance of the existing state-of-the-art adversarial attack methods. Meanwhile, we show that the adversarial training using examples generated from LASA makes the classifier more robust. We expect that our methods can be applied as a bench-mark of adversarial attacks on SSS images, motivating future research to design novel neural networks or defensive methods to resist real-world adversarial attacks on SSS images. (c) 2023 Elsevier Ltd. All rights reserved.
Keyword:
Adversarial attack
Classification
Side-scan sonar
Lambertian model

期刊

Pattern Recognition 封面图
Pattern Recognition
IF:
7.6
论文数:
1.3W
被引数:
4.5W

机构

S
southeast university - china
学者数:
5.3W
论文数: 4.9W
被引数: 57
引用论文

引用论文

Vision in Multiple Sclerosis
err2011-12-01
err0
errOAAI
errReiko E. Sakai; Daniel J. Feller; Kristin M. Galetta; Steven L. Galetta; Laura J. Balcer
err分享
err收藏
Do Materialistic Adolescents Ruminate More About Their Social Media Posts?
err2020-12-31
err0
PREAI
errKeeley Hynes; Daniel G. Lannin; Jeremy B. Kanter; Ani Yazedjian; Margaret M. Nauta
err分享
err收藏
Resistance Training and Youth阻力训练和青年
err1989-11-01
err0
errOAAI
errWilliam J. Kraemer; Andrew C. Fry; Peter N. Frykman; Brian Conroy; Jay Hoffman
err分享
err收藏
Semi-supervised robust training with generalized perturbed neighborhood
err2022-04-01
err26
PREAI
errLi, Yiming; Wu, Baoyuan; Feng, Yan; Fan, Yanbo; Jiang, Yong; Li, Zhifeng; Xia, Shu-Tao
err分享
err收藏
err分享
err收藏
err分享
err收藏
学者 查看更多内容