We analyze the performance of semantic segmentation models w.r.t. adversarial attacks. We observe that the adversarial examples generated from a source model fail to attack the target models, i.e. the conventional attack methods [1, 2] do not transfer well to the target models, making it necessary to study the transferable attacks, in particular transferable attacks for semantic segmentation. We thoroughly analysis existing transferable attacks for image classification, and extend them to semantic segmentation. With extensive investigation, we find two main factors for effective transferable attack. Firstly, the attack should come with data augmentation and translation-invariant features to deal with unseen models. Secondly, stabilized optimization strategies are needed to find the optimal attack direction.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Transferable Attacks for Semantic Segmentation

  • Mengqi He,
  • Jing Zhang,
  • Xin Yu

摘要

We analyze the performance of semantic segmentation models w.r.t. adversarial attacks. We observe that the adversarial examples generated from a source model fail to attack the target models, i.e. the conventional attack methods [1, 2] do not transfer well to the target models, making it necessary to study the transferable attacks, in particular transferable attacks for semantic segmentation. We thoroughly analysis existing transferable attacks for image classification, and extend them to semantic segmentation. With extensive investigation, we find two main factors for effective transferable attack. Firstly, the attack should come with data augmentation and translation-invariant features to deal with unseen models. Secondly, stabilized optimization strategies are needed to find the optimal attack direction.