Restricted-Area Adversarial Example Attack for Image Captioning Model

Author:

Kwon Hyun1ORCID,Kim SungHwan2ORCID

Affiliation:

1. Department of Artificial Intelligence and Data Science, Korea Military Academy, Seoul, Republic of Korea

2. Department of Applied Statistics, Konkuk University, Seoul, Republic of Korea

Abstract

Deep neural networks provide good performance in the fields of image recognition, speech recognition, and text recognition. For example, recurrent neural networks are used by image captioning models to generate text after an image recognition step, thereby providing captions for the images. The image captioning model first extracts features from the image and generates a representation vector; it then generates the text for the image captions by using the recursive neural network. This model has a weakness, however: it is vulnerable to adversarial examples. In this paper, we propose a method for generating restricted adversarial examples that target image captioning models. By adding a minimal amount of noise just to a specific area of an original sample image, the proposed method creates an adversarial example that remains correctly recognizable to humans yet is misinterpreted by the target model. We evaluated the method’s performance through experiments with the MS COCO dataset and using TensorFlow as the machine learning library. The results show that the proposed method generates a restricted adversarial example that is misinterpreted by the target model while minimizing its distortion from the original sample.

Funder

Ministry of Education, Science and Technology

Publisher

Hindawi Limited

Subject

Electrical and Electronic Engineering,Computer Networks and Communications,Information Systems

Reference39 articles.

1. Deep learning in neural networks: An overview

2. Very deep convolutional networks for large-scale image recognition;K. Simonyan,2014

3. ISNet: Towards Improving Separability for Remote Sensing Image Change Detection

4. Deep Neural Networks for Acoustic Modeling in Speech Recognition: The Shared Views of Four Research Groups

5. A unified architecture for natural language processing: deep neural networks with multitask learning;R. Collobert

Cited by 3 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

1. Black-Box Attacks on Image Activity Prediction and its Natural Language Explanations;2023 IEEE/CVF International Conference on Computer Vision Workshops (ICCVW);2023-10-02

2. Denoising by Decorated Noise: An Interpretability-Based Framework for Adversarial Example Detection;Wireless Communications and Mobile Computing;2023-04-11

3. Toward Backdoor Attacks for Image Captioning Model in Deep Neural Networks;Security and Communication Networks;2022-08-16

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3