Full metadata record
| DC Field | Value | Language |
|---|---|---|
| dc.contributor | Department of Computing | en_US |
| dc.contributor.advisor | Li, Qing (COMP) | en_US |
| dc.creator | Dai, Zeyu | - |
| dc.identifier.uri | https://theses.lib.polyu.edu.hk/handle/200/14401 | - |
| dc.language | English | en_US |
| dc.publisher | Hong Kong Polytechnic University | en_US |
| dc.rights | All rights reserved | en_US |
| dc.title | Imperceptible adversarial attacks in images | en_US |
| dcterms.abstract | In the last decades, benefiting from massive data and huge computation resources, deep neural networks (DNNs) have achieved significant progress in wide applications, such as image classification, object detection, natural language processing, and machine translation. Especially in image domain, DNNs with plenty of hidden layers and complicated architectures can capture useful and semantic visual patterns, and realize various tasks with a high confidence. | en_US |
| dcterms.abstract | Despite these achievements, the safety and robustness of DNN systems become critical and attract more attention from research community. In 2013, DNNs were first found vulnerable to adversarial examples (AEs), that a slight perturbation of the images can lead to classifiers making erroneous prediction. This discovery unveiled the vulnerability of DNNs, which is a critical threat especially for some security-sensitive scenarios, such as autonomous driving where DNNs are used to recognize road signs. Adversarial attack is the process of generating AEs. It has two main goals: 1) attack successfulness, i.e., generate AEs that can successfully fool DNN models; 2) imperceptibility, i.e., ensure the difference between the generated AEs and real-world images imperceptible. | en_US |
| dcterms.abstract | Although existing works have achieved very high attack success rate (ASR) in various attack settings, there is still a gap between the generated AEs and real-world images in terms of imperceptibility. On the one hand, achieving imperceptibility is basically contradictory to the goal of attack successfulness, most works achieve high ASR at the cost of imperceptibility performance. On the other hand, how to define and evaluate imperceptibility is still an open question. Most works use Lp norms, such as L0, L2 and L∞ to quantify the magnitude of the perturbation added to the original images. However, Lp norms are found non-suitable for simulating human vision system (HVS) in subjective experiments, not to mention some special attack tasks and settings where Lp norms are not applicable. | en_US |
| dcterms.abstract | To fill in the research gap, this thesis aims to explore and enhance imperceptible adversarial attacks systematically. First, we propose a thorough taxonomy of AEs based on their mathematical definitions to classify all types of AEs into three main categories, i.e., input-specific AE, input-agnostic AE and input-free AE. Input-specific AE is generated based on a specific clean image, input-agnostic AE refers to apply a universal perturbation or transformation to any clean image to be adversarial, and input-free AE does not rely on given clean images and can be generated infinitely. Moreover, we study the imperceptibility of AEs from two perspectives: human imperceptibility and machine imperceptibility. Human imperceptibility focuses on the human capability to recognize AEs from real-world images, while machine imperceptibility refers to the research on whether machines can detect AEs. | en_US |
| dcterms.abstract | Based on the above investigation, we then explore different imperceptible adversarial attacks for three types of AEs in image classification domain, considering both human and machine imperceptibility: | en_US |
| dcterms.abstract | 1. Our first work focuses on black-box input-specific attack setting, where global perturbation and high-frequency noises are used to pursue query-efficient attacks at the cost of imperceptibility. We propose Saliency Attack to restrict the perturbations to a small but classifier-sensitive region, and further refine the perturbations to generate efficient and imperceptible input-specific AEs in black-box setting. | en_US |
| dcterms.abstract | 2. Our second work studies both human and machine imperceptibility in input-agnostic attack setting. Considering the interpretation discrepancy between the clean images and their AEs that could be used to detect AEs, we propose Joint Universal Adversarial Perturbations (JUAP) to generate imperceptible universal perturbations by jointly optimizing the adversarial loss and interpretation discrepancy. | en_US |
| dcterms.abstract | 3. Our third work explores the most general input-free AEs, which are generated without any input clean images. Given the poor naturalness of existing input-free attack methods, we propose SemDiff to utilize the semantic latent space of diffusion models to generate natural input-free AEs with semantically meaningful attribute shifts. | en_US |
| dcterms.abstract | Extensive experiments on various tasks and datasets demonstrate the effectiveness of our proposed methods in generating more imperceptible and threatening AEs for different types of AEs, which also provide new insights into the robustness and security of DNNs. | en_US |
| dcterms.extent | xix, 163 pages : color illustrations | en_US |
| dcterms.isPartOf | PolyU Electronic Theses | en_US |
| dcterms.issued | 2026 | en_US |
| dcterms.educationalLevel | Ph.D. | en_US |
| dcterms.educationalLevel | All Doctorate | en_US |
| dcterms.accessRights | open access | en_US |
Copyright Undertaking
As a bona fide Library user, I declare that:
- I will abide by the rules and legal ordinances governing copyright regarding the use of the Database.
- I will use the Database for the purpose of my research or private study only and not for circulation or further reproduction or any other purpose.
- I agree to indemnify and hold the University harmless from and against any loss, damage, cost, liability or expenses arising from copyright infringement or unauthorized usage.
By downloading any item(s) listed above, you acknowledge that you have read and understood the copyright undertaking as stated above, and agree to be bound by all of its terms.
Please use this identifier to cite or link to this item:
https://theses.lib.polyu.edu.hk/handle/200/14401

