Pasadena: Perceptually Aware and Stealthy Adversarial Denoise Attack
- URL: http://arxiv.org/abs/2007.07097v3
- Date: Tue, 24 Aug 2021 07:47:28 GMT
- Title: Pasadena: Perceptually Aware and Stealthy Adversarial Denoise Attack
- Authors: Yupeng Cheng, Qing Guo, Felix Juefei-Xu, Wei Feng, Shang-Wei Lin,
Weisi Lin, Yang Liu
- Abstract summary: Image denoising can remove noise that widely exists in images captured by multimedia devices due to low-quality imaging sensors, unstable image transmission processes, or low light conditions.
Recent works also find that image denoising benefits the high-level vision tasks, e.g., image classification.
In this work, we try to challenge this common sense and explore a totally new problem, i.e., whether the image denoising can be given the capability of fooling the state-of-the-art deep neural networks (DNNs) while enhancing the image quality.
- Score: 45.74991480637961
- License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/
- Abstract: Image denoising can remove natural noise that widely exists in images
captured by multimedia devices due to low-quality imaging sensors, unstable
image transmission processes, or low light conditions. Recent works also find
that image denoising benefits the high-level vision tasks, e.g., image
classification. In this work, we try to challenge this common sense and explore
a totally new problem, i.e., whether the image denoising can be given the
capability of fooling the state-of-the-art deep neural networks (DNNs) while
enhancing the image quality. To this end, we initiate the very first attempt to
study this problem from the perspective of adversarial attack and propose the
adversarial denoise attack. More specifically, our main contributions are
three-fold: First, we identify a new task that stealthily embeds attacks inside
the image denoising module widely deployed in multimedia devices as an image
post-processing operation to simultaneously enhance the visual image quality
and fool DNNs. Second, we formulate this new task as a kernel prediction
problem for image filtering and propose the adversarial-denoising kernel
prediction that can produce adversarial-noiseless kernels for effective
denoising and adversarial attacking simultaneously. Third, we implement an
adaptive perceptual region localization to identify semantic-related
vulnerability regions with which the attack can be more effective while not
doing too much harm to the denoising. We name the proposed method as Pasadena
(Perceptually Aware and Stealthy Adversarial DENoise Attack) and validate our
method on the NeurIPS'17 adversarial competition dataset, CVPR2021-AIC-VI:
unrestricted adversarial attacks on ImageNet,etc. The comprehensive evaluation
and analysis demonstrate that our method not only realizes denoising but also
achieves a significantly higher success rate and transferability over
state-of-the-art attacks.
Related papers
- Neighboring Slice Noise2Noise: Self-Supervised Medical Image Denoising from Single Noisy Image Volume [12.077993066353294]
We propose a novel self-supervised medical image denoising method, Neighboring Slice Noise2Noise (NS-N2N)
NS-N2N only requires a single noisy image volume obtained from one medical imaging procedure to achieve high-quality denoising of the image volume itself.
arXiv Detail & Related papers (2024-11-16T16:24:28Z) - Dual Adversarial Resilience for Collaborating Robust Underwater Image
Enhancement and Perception [54.672052775549]
In this work, we introduce a collaborative adversarial resilience network, dubbed CARNet, for underwater image enhancement and subsequent detection tasks.
We propose a synchronized attack training strategy with both visual-driven and perception-driven attacks enabling the network to discern and remove various types of attacks.
Experiments demonstrate that the proposed method outputs visually appealing enhancement images and perform averagely 6.71% higher detection mAP than state-of-the-art methods.
arXiv Detail & Related papers (2023-09-03T06:52:05Z) - Masked Image Training for Generalizable Deep Image Denoising [53.03126421917465]
We present a novel approach to enhance the generalization performance of denoising networks.
Our method involves masking random pixels of the input image and reconstructing the missing information during training.
Our approach exhibits better generalization ability than other deep learning models and is directly applicable to real-world scenarios.
arXiv Detail & Related papers (2023-03-23T09:33:44Z) - Enhancing convolutional neural network generalizability via low-rank weight approximation [6.763245393373041]
Sufficient denoising is often an important first step for image processing.
Deep neural networks (DNNs) have been widely used for image denoising.
We introduce a new self-supervised framework for image denoising based on the Tucker low-rank tensor approximation.
arXiv Detail & Related papers (2022-09-26T14:11:05Z) - Zero-shot Blind Image Denoising via Implicit Neural Representations [77.79032012459243]
We propose an alternative denoising strategy that leverages the architectural inductive bias of implicit neural representations (INRs)
We show that our method outperforms existing zero-shot denoising methods under an extensive set of low-noise or real-noise scenarios.
arXiv Detail & Related papers (2022-04-05T12:46:36Z) - Practical Blind Image Denoising via Swin-Conv-UNet and Data Synthesis [148.16279746287452]
We propose a swin-conv block to incorporate the local modeling ability of residual convolutional layer and non-local modeling ability of swin transformer block.
For the training data synthesis, we design a practical noise degradation model which takes into consideration different kinds of noise.
Experiments on AGWN removal and real image denoising demonstrate that the new network architecture design achieves state-of-the-art performance.
arXiv Detail & Related papers (2022-03-24T18:11:31Z) - Geodesic Gramian Denoising Applied to the Images Contaminated With Noise
Sampled From Diverse Probability Distributions [0.2578242050187029]
Gramian-based filtering scheme to remove noise sampled from five prominent probability distributions from selected images.
Method preserves image smoothness by adopting patches partitioned from the image, rather than pixels.
We validate its denoising performance, using three benchmark computer vision test images applied to two state-of-the-art denoising methods.
arXiv Detail & Related papers (2022-03-04T22:48:12Z) - Dual Adversarial Network: Toward Real-world Noise Removal and Noise
Generation [52.75909685172843]
Real-world image noise removal is a long-standing yet very challenging task in computer vision.
We propose a novel unified framework to deal with the noise removal and noise generation tasks.
Our method learns the joint distribution of the clean-noisy image pairs.
arXiv Detail & Related papers (2020-07-12T09:16:06Z) - Adversarial Attacks on Convolutional Neural Networks in Facial
Recognition Domain [2.4704085162861693]
Adversarial attacks that render Deep Neural Network (DNN) classifiers vulnerable in real life represent a serious threat in autonomous vehicles, malware filters, or biometric authentication systems.
We apply Fast Gradient Sign Method to introduce perturbations to a facial image dataset and then test the output on a different classifier.
We craft a variety of different black-box attack algorithms on a facial image dataset assuming minimal adversarial knowledge.
arXiv Detail & Related papers (2020-01-30T00:25:05Z)
This list is automatically generated from the titles and abstracts of the papers in this site.
This site does not guarantee the quality of this site (including all information) and is not responsible for any consequences.