NIPS 2018 Adversarial Vision Challenge aims to improve machine vision models.
problem Improving robustness of machine vision models and adversarial attacks.
method Organized a competition to measure progress in adversarial machine vision.
result Facilitated measurable progress in adversarial machine vision.
New datasets make AI models fail reliably, highlighting weaknesses.
problem AI models' vulnerabilities to adversarial examples.
method Created challenging datasets with adversarial filtering, tested on various models.
result Existing models perform poorly on new datasets, revealing shared weaknesses.
This paper surveys black-box attacks on computer vision models.
problem Real-life adversarial attacks on deep learning models.
method Comprehensive comparative study of attacks and defenses.
result Significant amount of research on reliability of models.
Efficiently attacks black-box image classifiers using biased sampling.
problem Efficiently attacking black-box image classifiers without access to confidence scores.
method Reinterpreting Boundary Attacks as a biased sampling framework.
result Combination of biases outperforms state of the art by a wide margin.
Machine learning models are vulnerable to adversarial examples: small changes to images can cause computer vision models to make mistakes such as identifying a school bus as an ostrich. However, it is still an open question whether humans are prone to similar mistakes. Here, we address this question by leveraging recen…
Robust CLIP improves vision models' resistance to attacks.
problem Vulnerability of vision models to adversarial attacks.
method Unsupervised adversarial fine-tuning of CLIP.
result Robust CLIP prevents stealth attacks on vision models.
This work uses image generation models to find vision model bugs.
problem Automatically discovering failures in vision models.
method Conditional text-to-image generation and captioning models.
result Demonstrated utility of large-scale generative models to find vision model bugs.
New insights into data augmentation for improving robustness in computer vision.
problem Challenges in achieving robustness to distributional shift in computer vision.
method Investigation of trade-offs between robustness to high and low frequency corruptions using Gaussian data augmentation and adversarial training.
result Improvements in robustness to high frequency corruptions come at the cost of reduced robustness to low frequency corruptions.
ADAPT improves robustness of Vision Transformers without full model fine-tuning.
problem Vulnerability of Vision Transformers to adversarial attacks.
method Parameter-efficient prompt tuning with ADAPT framework for adaptive adversarial training.
result ADAPT achieves robust accuracy of ~40% w.r.t. SOTA methods using only ~1% of the parameters.
Local convolutions bias neural networks towards high-frequency adversarial examples.
problem High-frequency adversarial examples in neural networks.
method Analysis of different linear and nonlinear architectures, focusing on the impact of local convolution operations.
result Local convolutions induce an implicit bias towards high frequency features, leading to high-frequency adversarial examples.
New method trades off adversarial robustness for accuracy.
problem Trade-off between adversarial robustness and accuracy.
method Decomposes robust error into natural and boundary errors, provides a tight upper bound, and designs TRADES defense.
result TRADES method outperforms in adversarial vision challenge.
The paper proposes logit regularization for improving neural network robustness against adversarial attacks.
problem Vulnerability of neural networks to adversarial examples, especially in safety-critical applications.
method Logit regularization techniques combined with other methods to enhance adversarial robustness.
result Logit regularization can improve the effectiveness of existing adversarial defenses and create stronger black-box attacks.
Paper presents certified defenses against adversarial patch attacks.
problem Certified defenses against adversarial patch attacks are needed.
method Proposes the first certified defense and faster training methods.
result Demonstrates robustness transfer across different patch shapes.
A new neural network model enhances adversarial robustness without sacrificing task performance.
problem Adversarial attacks on neural networks deployed in real-world scenarios.
method Proposes a novel neural network paradigm where each parameter is modeled as a statistical distribution with learnable parameters.
result Demonstrates highly robust performance to various adversarial attacks while maintaining task-specific performance.
New metric measures deep learning robustness to noise.
problem Deep learning models are vulnerable to noise.
method Formal definition of robustness as localized Lipschitz constant.
result New metric evaluated on competitive vision datasets.
Introduces PCG for better counterfactual explanations in vision models.
problem Ambiguity in latent-space optimization methods for counterfactual explanations.
method Constructs counterfactuals by tracing geodesics under a perceptually Riemannian metric.
result PCG outperforms baselines and reveals hidden failure modes.
One of the main challenges in the parametrization of geological models is the ability to capture complex geological structures often observed in the subsurface. In recent years, generative adversarial networks (GAN) were proposed as an efficient method for the generation and parametrization of complex data, showing sta…
Computer vision models are unstable due to task symmetries and labelling issues.
problem Instability of computer vision models in classification tasks.
method Analysis of symmetries, categorical nature, and labelling issues.
result Instability is a necessary result of current computer vision formulation.
New mechanisms from primate vision improve neural network robustness.
problem Demonstrating robust neural networks to small adversarial perturbations.
method Investigated two biologically plausible mechanisms: non-uniform retina sampling and receptive field diversity.
result Non-uniform retina sampling and receptive field diversity improve adversarial robustness.
Paper proposes methods to reduce adversarial vulnerability in neural networks.
problem Adversarial vulnerability of deep neural networks in safety-critical applications.
method Defining vulnerability, proposing Vulnerability Suppression (VS) loss, and a Bayesian feature pruning method.
result Improves adversarial robustness and clean example performance with minimal parameter reduction.
A structured approach to generating adversarial attacks for ML systems.
problem Vulnerability of ML systems to adversarial perturbations.
method Developed an 'attack generator' to systematically create adversarial attacks.
result Summarized and extended existing adversarial perturbation taxonomies.
MimicGAN learns to recover images from corrupted data without supervision.
problem Recovering images from corrupted data without known prior information.
method Generative adversarial networks (GANs) to learn corruption mimicking.
result MimicGAN outperforms existing techniques in blind image recovery and adversarial defense.
PyFi uses adversarial agents to train VLMs on financial image understanding.
problem Training VLMs to understand complex financial questions.
method PyFi-600K dataset and adversarial MCTS mechanism.
result Fine-tuned VLMs improve by 19.52% and 8.06% on financial question accuracy.
QUAM improves uncertainty quantification in deep learning models.
problem Estimating epistemic uncertainty in deep learning models.
method QUAM identifies regions with high divergence between predictions and a reference model.
result QUAM has lower approximation error of epistemic uncertainty compared to previous methods.
A new adversarial DBN framework for deep learning.
problem Training deep belief networks (DBNs) efficiently and with scalability.
method Replacing generator in GANs with DBN and developing a parallelizable training algorithm.
result Framework can be applied to general DBNs without backpropagation.
Deep neural networks have been widely adopted in recent years, exhibiting impressive performances in several application domains. It has however been shown that they can be fooled by adversarial examples, i.e., images altered by a barely-perceivable adversarial noise, carefully crafted to mislead classification. In thi…
Though CNNs have achieved the state-of-the-art performance on various vision tasks, they are vulnerable to adversarial examples --- crafted by adding human-imperceptible perturbations to clean images. However, most of the existing adversarial attacks only achieve relatively low success rates under the challenging black…
Deep neural networks have lately shown tremendous performance in various applications including vision and speech processing tasks. However, alongside their ability to perform these tasks with such high accuracy, it has been shown that they are highly susceptible to adversarial attacks: a small change in the input woul…
Top 8 robotic vision systems tackled lifelong object recognition challenges.
problem Lifelong learning in robotic vision for varied, dynamic environments.
method Design of a dataset with diverse conditions and rules for evaluation.
result Robotic vision systems improved over time with dynamic object appearances.
Current neural network-based classifiers are susceptible to adversarial examples even in the black-box setting, where the attacker only has query access to the model. In practice, the threat model for real-world systems is often more restrictive than the typical black-box model where the adversary can observe the full …
Deep Neural Networks(DNN) have excessively advanced the field of computer vision by achieving state of the art performance in various vision tasks. These results are not limited to the field of vision but can also be seen in speech recognition and machine translation tasks. Recently, DNNs are found to poorly fail when …
Adversarial attacks can fool self-driving cars, changing steering predictions.
problem Security of deep neural networks in self-driving cars.
method Demonstrated adversarial attacks on steering angle prediction model.
result Small image modifications can mislead self-driving car predictions.
Given the ability to directly manipulate image pixels in the digital input space, an adversary can easily generate imperceptible perturbations to fool a Deep Neural Network (DNN) image classifier, as demonstrated in prior work. In this work, we propose ShapeShifter, an attack that tackles the more challenging problem o…
AI models aligned with human vision perform well on few data tasks.
problem Few-shot learning performance with limited data.
method Information-theoretic analysis and empirical testing of 491 models.
result Highly aligned models show better robustness to attacks and domain shifts.
AFLite filters dataset biases to improve model generalization.
problem Overfitting to dataset biases degrades model performance on out-of-distribution samples.
method AFLite adversarially filters dataset biases, reducing their impact on model performance.
result Filtered datasets yield better generalization to out-of-distribution tasks.
DA-RNN predicts driving maneuvers up to 3 seconds ahead.
problem Adapting driving model to new drivers and vehicles.
method Domain-Adversarial Recurrent Neural Network (DA-RNN) for robust predictions.
result DA-RNN improves performance by 30% in real drivers and 114% in simulations.
We find ways to make physical signals misclassified by computer vision models.
problem Vulnerability of signal classifiers to adversarial perturbations in physical signals.
method Solving PDE-constrained optimization problems to construct imperceptible perturbations.
result Effective and physically realizable adversarial perturbations can be computed for machine learning models.
Adversarial attacks pose a threat to deep neural networks, especially in safety-critical applications.
problem Adversarial attacks can misclassify deep neural networks, leading to safety issues.
method Adversarial attacks are categorized into white-box and black-box attacks based on the attacker's knowledge. They can be targeted or non-targeted.
result Adversarial attacks are effective and can transfer between different models and real-world scenarios.
This paper shows excessive invariance in adversarial robust models can make them more vulnerable to certain types of attacks.
problem Excessive invariance in adversarial robust models can make them more vulnerable to certain types of attacks.
method Analytical constructions and empirical studies of vision classifiers with state-of-the-art robustness to perturbation-based adversaries constrained by an ℓp norm. result Robustness to perturbation-based adversarial examples does not guarantee general robustness and can increase vulnerability to invariance-based adversarial examples.
Paper defends against adversarial videos by detecting and reducing imperceptible perturbations.
problem Adversarial videos can fool well-trained video classification models.
method Temporal consistency between frames and spatial denoising to detect and reduce perturbations.
result The proposed method significantly improves robustness against adversarial attacks.
Paper uses 'manifold attack' to improve model accuracy and robustness.
problem Improving model performance with limited training data and large model parameters.
method Enforces manifold preservation from original data into latent space using adversarial learning.
result Improves accuracy rate and robustness to adversarial examples.
Systematic review of machine vision in robotics, highlighting challenges and improvements.
problem Challenges in machine vision for robotics, especially occlusion and lighting variance.
method Systematic literature review of 172 papers from four databases, selecting 52 relevant papers.
result Robustness and computation time improvements, but occlusion and lighting variance remain major issues.
This paper improves ensemble learning for vision tasks by encouraging diversity in predictions.
problem Generating effective ensembles of neural networks for multi-modal data.
method Explicitly optimize a diversity inducing adversarial loss for learning stochastic latent variables.
result Significant improvements in classification accuracy and out-of-distribution detection compared to baselines.
Visual Domain Adaptation is a problem of immense importance in computer vision. Previous approaches showcase the inability of even deep neural networks to learn informative representations across domain shift. This problem is more severe for tasks where acquiring hand labeled data is extremely hard and tedious. In this…
Project aims to improve robot vision by adapting to new environments.
problem Robots struggle to recognize objects in new settings.
method Selected and evaluated state-of-the-art DA methods on various datasets.
result Training a good object classifier remains challenging.
P-BO reduces black-box adversarial attacks by 10x with Bayesian optimization and function prior.
problem Efficiently generating adversarial examples against black-box models.
method Prior-guided Bayesian Optimization (P-BO) with a function prior initialized from a surrogate model.
result Significantly reduces the number of queries needed for adversarial attacks.
Deep neural networks are vulnerable to adversarial attacks in time series classification.
problem Vulnerability of deep learning models to adversarial time series examples.
method Proposed adversarial attack mechanisms to add noise to input time series.
result Current state-of-the-art deep learning time series classifiers are vulnerable to adversarial attacks.
VERA-V uses variational inference to discover vulnerabilities in multimodal vision-language models.
problem Existing methods for jailbreaking vision-language models are brittle, limited, and focus on single attacks.
method VERA-V recasts jailbreak discovery as learning a joint posterior distribution over text-image prompts, using variational inference and three complementary strategies.
result VERA-V consistently outperforms state-of-the-art baselines, achieving up to 53.75% higher attack success rate.