about
PatchAttack: A black-box texture-based attack with reinforcement learning (arxiv.org)
47 points by jchook on Apr 17, 2020 | hide | past | pdf | 10 comments on HN

In plain words: It sticks small textured patches on an image and uses trial-and-error learning that asks the model few questions to pick their spot and class-based texture. It fools ImageNet models over 99% of the time, touching 3% of the image, or 10% for targeted attacks.

Abstract · PatchAttack: A Black-box Texture-based Attack with Reinforcement Learning

Patch-based attacks introduce a perceptible but localized change to the input that induces misclassification. A limitation of current patch-based black-box attacks is that they perform poorly for targeted attacks, and even for the less challenging non-targeted scenarios, they require a large number of queries. Our proposed PatchAttack is query efficient and can break models for both targeted and non-targeted attacks. PatchAttack induces misclassifications by superimposing small textured patches on the input image. We parametrize the appearance of these patches by a dictionary of class-specific textures. This texture dictionary is learned by clustering Gram matrices of feature activations from a VGG backbone. PatchAttack optimizes the position and texture parameters of each patch using reinforcement learning. Our experiments show that PatchAttack achieves > 99% success rate on ImageNet for a wide range of architectures, while only manipulating 3% of the image for non-targeted attacks and 10% on average for targeted attacks. Furthermore, we show that PatchAttack circumvents state-of-the-art adversarial defense methods successfully.

Chenglin Yang, Adam Kortylewski, Cihang Xie, Yinzhi Cao, Alan Yuille
arXiv:2004.05682 · cs.CV · submitted Apr 12, 2020 · updated Jul 19, 2020
abstract · pdf · html · To appear in ECCV 2020

add comment on HN

Help me out. I am naive about neural networks. I have skimmed the paper, read the abstract and he conclusion and looked at the examples.

Does this not illustrate what is the fatal flaw in image recognition based approaches with neural networks, that their failure modes are inscrutable?

80% or 95% of the time they do well but the corner cases where they do poorly they fail in ways that are entirely unlike the was our brains' systems fail. Unpredictably. So they can be useful for non critical applications but not critical applications. Like self driving cars....

Stages of grief here... I was looking forward to my car with a cocktail cabinet that would drive me to parties and home again... I believed the hype five years ago. Is this why progress has stalled?

Not a full answer, but specifically for image recognition, there's been some exciting work by Chris Olah and others to visualize exactly what's going on in neural networks. Some of this work has been really fascinating, identifying what specific neurons or sub-networks seem to focus on.

One overview can be found here: https://distill.pub/2018/building-blocks/

So I think others in the space have the same frustrations about the lack of insight into these models, and we're working on ways to get better answers out of these black boxes.

Shower thought: vinyl car wrap with a bunch of pictures of stop lights at various angles
"Reckless endangerment: A person commits the crime of reckless endangerment if the person recklessly engages in conduct which creates substantial jeopardy of severe corporeal trauma to another person."

https://en.m.wikipedia.org/wiki/Endangerment

Here in New Zealand you cannot legally place images of official road signs next to or near roads. If you wanted to illegally stop vehicles, there are cheaper ways of blocking a road!
Some sort of rule on top can simply negate this by requiring x amount of area with respect to the image
Original title was "PatchAttack: A Black-box Texture-based Attack with Reinforcement Learning" which seems better. The phrase "99% with black-box RL" is particularly inscrutable.
Changed now. Thanks. Submitted title was "PatchAttack: Image classifier adversarial attack, 99% with black-box RL".

Submitters: please use the original title and then, if you like, add a comment to the thread explaining what you think is important about the article. You'll have more room for your explanation that way, people won't complain, and you won't be breaking the site guidelines: https://news.ycombinator.com/newsguidelines.html

Is there a policy for shortening long original titles? Some research papers can be a bit wordy in their titles.