Fabrizio Falchi
ISTI, CNR, Pisa, italy
www.fabriziofalchi.it
ATTACKING DEEP NEURAL NETWORKS
WITH ADVERSARIAL IMAGES
COST ACTION CA16101 - Dubrovnik, November 7th
fabrizio.falchi@cnr.it fabrizio.falchi@cnr.it - - PowerPoint PPT Presentation
A TTACKING D EEP N EURAL N ETWORKS WITH A DVERSARIAL I MAGES Fabrizio Falchi ISTI, CNR, Pisa, italy www.fabriziofalchi.it COST ACTION CA16101 - Dubrovnik, November 7th fabrizio.falchi@cnr.it fabrizio.falchi@cnr.it fabrizio.falchi@cnr.it W HAT
ISTI, CNR, Pisa, italy
www.fabriziofalchi.it
COST ACTION CA16101 - Dubrovnik, November 7th
fabrizio.falchi@cnr.it
fabrizio.falchi@cnr.it
fabrizio.falchi@cnr.it
fabrizio.falchi@cnr.it
fabrizio.falchi@cnr.it
fabrizio.falchi@cnr.it
fabrizio.falchi@cnr.it
fabrizio.falchi@cnr.it
fabrizio.falchi@cnr.it
Edward H. Adelson
fabrizio.falchi@cnr.it
Edward H. Adelson
fabrizio.falchi@cnr.it
fabrizio.falchi@cnr.it
DUBROVNIK
fabrizio.falchi@cnr.it
fabrizio.falchi@cnr.it
fabrizio.falchi@cnr.it
… Mushrooms Pineapple Toucan …
fabrizio.falchi@cnr.it
19
… Mushrooms <whatever> …
fabrizio.falchi@cnr.it
20
… Mushrooms Toucan …
fabrizio.falchi@cnr.it
fabrizio.falchi@cnr.it
Slide credit: Biggio
fabrizio.falchi@cnr.it
fabrizio.falchi@cnr.it
Practical Black-Box Attacks against Machine Learning Nicolas Papernot, Patrick McDaniel, Ian Goodfellow, Somesh Jha, Z. Berkay Celik, Ananthram Swami
fabrizio.falchi@cnr.it
Fast Geometrically-Perturbed Adversarial Faces Ali Dabouei, Sobhan Soleymani, Jeremy Dawson, Nasser M. Nasrabadi
fabrizio.falchi@cnr.it
Fast Geometrically-Perturbed Adversarial Faces Ali Dabouei, Sobhan Soleymani, Jeremy Dawson, Nasser M. Nasrabadi
fabrizio.falchi@cnr.it
Fast Geometrically-Perturbed Adversarial Faces Ali Dabouei, Sobhan Soleymani, Jeremy Dawson, Nasser M. Nasrabadi
fabrizio.falchi@cnr.it
Fast Geometrically-Perturbed Adversarial Faces Ali Dabouei, Sobhan Soleymani, Jeremy Dawson, Nasser M. Nasrabadi
fabrizio.falchi@cnr.it
Fast Geometrically-Perturbed Adversarial Faces Ali Dabouei, Sobhan Soleymani, Jeremy Dawson, Nasser M. Nasrabadi
fabrizio.falchi@cnr.it
Fast Geometrically-Perturbed Adversarial Faces Ali Dabouei, Sobhan Soleymani, Jeremy Dawson, Nasser M. Nasrabadi
fabrizio.falchi@cnr.it
33 Photo: labsix
fabrizio.falchi@cnr.it
34 Photo: labsix
fabrizio.falchi@cnr.it
fabrizio.falchi@cnr.it
36
fabrizio.falchi@cnr.it
Robust Physical-World Attacks on Deep Learning Models Eykholt, Evtimov, Fernandes, Bo Li, Rahmati, Xiao, Prakash, Kohno, Song
fabrizio.falchi@cnr.it
fabrizio.falchi@cnr.it
Adversarial Generative Nets: Neural Network Attacks on State-of-the-Art Face Recognition Mahmood Sharif, Sruti Bhagavatula, Lujo Bauer, Michael K. Reiter
fabrizio.falchi@cnr.it
Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face Recognition Mahmood Sharif, Sruti Bhagavatula, Lujo Bauer, Michael K. Reiter
fabrizio.falchi@cnr.it
Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face Recognition Mahmood Sharif, Sruti Bhagavatula, Lujo Bauer, Michael K. Reiter
fabrizio.falchi@cnr.it
Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face Recognition Mahmood Sharif, Sruti Bhagavatula, Lujo Bauer, Michael K. Reiter
fabrizio.falchi@cnr.it
fabrizio.falchi@cnr.it
fabrizio.falchi@cnr.it
Unravelling Robustness of Deep Learning based Face Recognition Against Adversarial Attacks Goswami, Ratha, Agarwal, Singh, Vatsa
46
fabrizio.falchi@cnr.it
Unravelling Robustness of Deep Learning based Face Recognition Against Adversarial Attacks Goswami, Ratha, Agarwal, Singh, Vatsa
47
fabrizio.falchi@cnr.it
49
Machine learning system should be aware of the arms race with the adversary
Security evaluation of pattern classifiers under attack Biggio, Fumera, Roli
fabrizio.falchi@cnr.it
fabrizio.falchi@cnr.it
52
… Mushrooms Pineapple Toucan …
fabrizio.falchi@cnr.it
53
… Mushrooms <whatever> …
fabrizio.falchi@cnr.it
54
… Mushrooms …
fabrizio.falchi@cnr.it
… Mushrooms …
55
fabrizio.falchi@cnr.it
Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face Recognition Mahmood Sharif, Sruti Bhagavatula, Lujo Bauer, Michael K. Reiter
fabrizio.falchi@cnr.it
AI
Machine Learning Repres. Learning Deep Learning
fabrizio.falchi@cnr.it
fabrizio.falchi@cnr.it
fabrizio.falchi@cnr.it
fabrizio.falchi@cnr.it
A detection scheme for adversarial images based on internal representation (aka deep features) of the neural network classifier.
the feature spaces, during the forward pass of the network.
can be used to discern them.
Adversarial examples detection in features distance spaces
ECCV WOCM Workshop 2018
fabrizio.falchi@cnr.it
fabrizio.falchi@cnr.it
fabrizio.falchi@cnr.it
66
fabrizio.falchi@cnr.it
fabrizio.falchi@cnr.it
Nicholas Carlini, David Wagner
Jan Hendrik Metzen, Tim Genewein, Volker Fischer, Bastian Bischoff
Mohammadreza, Friedhelm, Thilo
fabrizio.falchi@cnr.it
Detection of Face Morphing Attacks by Deep Learning
fabrizio.falchi@cnr.it
HiDDeN: Hiding Data With Deep Networks Jiren Zhu, Russell Kaplan, Justin Johnson, Li Fei-Fei
fabrizio.falchi@cnr.it
fabrizio.falchi@cnr.it
fabrizio.falchi@cnr.it
Questions are welcomed
Fabrizio Falchi
fabrizio.falchi@cnr.it
fabrizio.falchi@cnr.it