RUS  ENG
Full version
JOURNALS // Proceedings of the Institute for System Programming of the RAS // Archive

Proceedings of ISP RAS, 2022 Volume 34, Issue 6, Pages 101–116 (Mi tisp741)

This article is cited in 2 papers

Effect of transformations on the success of adversarial attacks for Clipped BagNet and ResNet image classifiers

E. O. Kurdenkovaa, M. S. Cherepninab, A. S. Chistyakovaac, K. V. Arkhipenkoa

a Ivannikov Institute for System Programming of the RAS
b Technical University of Munich
c Lomonosov Moscow State University

Abstract: Our paper compares the accuracy of the vanilla ResNet-18 model with the accuracy of the Clipped BagNet-33 and BagNet-33 models with adversarial learning under different conditions. We performed experiments on images attacked by the adversarial sticker under conditions of image transformations. The adversarial sticker is a small region of the attacked image, inside which the pixel values can be changed indefinitely, and this can generate errors in the model prediction. The transformations of the attacked images in this paper simulate the distortions that appear in the physical world when a change in perspective, scale or lighting changes the image. Our experiments show that models from the BagNet family perform poorly on images in low quality. We also analyzed the effects of different types of transformations on the models' robustness to adversarial attacks and the tolerance of these attacks.

Keywords: adversarial attack, adversarial patch, BagNet architecture, adversarial training, projected gradient descent

DOI: 10.15514/ISPRAS-2022-34(6)-7



© Steklov Math. Inst. of RAS, 2024