arrow
Return

Engineering pupil function for optical adversarial attacks

delete2022-02-14
delete4
delete
OA
AI
J
Jeongsoo Kim
S
Seungri Song
J
Jun-Ho Choi
C
Chulmin Joo *
J
Jong‐Seok Lee *
DOI:10.1364/OE.450058delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Adversarial attacks inject imperceptible noise to images to deteriorate the performance of deep image classification models. However, most of the existing studies consider attacks in the digital (pixel) domain where an image acquired by an image sensor with sampling and quantization is recorded. This paper, for the first time, introduces a scheme for optical adversarial attack, which physically alters the light field information arriving at the image sensor so that the classification model yields misclassification. We modulate the phase of the light in the Fourier domain using a spatial light modulator placed in the photographic system. The operative parameters of the modulator for adversarial attack are obtained by gradient-based optimization to maximize cross-entropy and minimize distortion. Experiments based on both simulation and a real optical system demonstrate the feasibility of the proposed optical attack. We show that our attack can conceal perturbations in the image more effectively than the existing pixel-domain attack. It is also verified that the proposed attack is completely different from common optical aberrations such as spherical aberration, defocus, and astigmatism in terms of both perturbation patterns and classification results. (C) 2022 Optica Publishing Group under the terms of the Optica Open Access Publishing Agreement

Journal

Optics Express cover
Optics Express
IF:
3.3
Papers:
6.1W
Citations:
14.3W

Organization

Y
Yonsei University
Scholars:
4.8W
Papers: 4.6W
Citations: 5.2W