Skip to main navigation Skip to search Skip to main content

When deep fool meets deep prior: Adversarial attack on super-resolution network

  • Tsinghua University
  • City University of Hong Kong

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

This paper investigates the vulnerability of the deep prior used in deep learning based image restoration. In particular, the image super-resolution, which relies on the strong prior information to regularize the solution space and plays important roles in the image pre-processing for future viewing and analysis, is shown to be vulnerable to the well-designed adversarial examples. We formulate the adversarial example generation process as an optimization problem, and given super-resolution model three different types of attack are designed based on the subsequent tasks: (i) style transfer attack; (ii) classification attack; (iii) caption attack. Another interesting property of our design is that the attack is hidden behind the super-resolution process, such that the utilization of low resolution images is not significantly influenced. We show that the vulnerability to adversarial examples could bring risks to the pre-processing modules such as super-resolution deep neural network, which is also of paramount significance for the security of the whole system. Our results also shed light on the potential security issues of the pre-processing modules, and raise concerns regarding the corresponding countermeasures for adversarial examples.

Original languageEnglish
Title of host publicationMM 2018 - Proceedings of the 2018 ACM Multimedia Conference
PublisherAssociation for Computing Machinery, Inc
Pages1930-1938
Number of pages9
ISBN (Electronic)9781450356657
DOIs
StatePublished - 15 Oct 2018
Externally publishedYes
Event26th ACM Multimedia conference, MM 2018 - Seoul, Korea, Republic of
Duration: 22 Oct 201826 Oct 2018

Publication series

NameMM 2018 - Proceedings of the 2018 ACM Multimedia Conference

Conference

Conference26th ACM Multimedia conference, MM 2018
Country/TerritoryKorea, Republic of
CitySeoul
Period22/10/1826/10/18

Keywords

  • Adversarial attack
  • Caption
  • Deep prior
  • Image classification
  • Style transfer
  • Super-resolution

Fingerprint

Dive into the research topics of 'When deep fool meets deep prior: Adversarial attack on super-resolution network'. Together they form a unique fingerprint.

Cite this