Towards Large yet Imperceptible Adversarial Image Perturbations with Perceptual Color Distance

  • 2019-11-06 16:27:32
  • Zhengyu Zhao, Zhuoran Liu, Martha Larson
  • 0

Abstract

The success of image perturbations that are designed to fool imageclassification is assessed in terms of both adversarial effect and visualimperceptibility. In this work, we investigate the contribution of human colorperception to perturbations that are not noticeable. Our basic insight is thatperceptual color distance makes it possible to drop the conventional assumptionthat imperceptible perturbations should strive for small $L_p$ norms in RGBspace. Our first approach, Perceptual Color distance C&W (PerC-C&W), extendsthe widely-used C&W approach and produces larger RGB perturbations. PerC-C&W isable to maintain adversarial strength, while contributing to imperceptibility.Our second approach, Perceptual Color distance Alternating Loss (PerC-AL),achieves the same outcome, but does so more efficiently by alternating betweenthe classification loss and perceptual color difference when updatingperturbations. Experimental evaluation shows PerC approaches improve robustnessand transferability of perturbations over conventional approaches and alsodemonstrates that the PerC distance can provide added value on top of existingstructure-based approaches to creating image perturbations.

 

Quick Read (beta)

loading the full paper ...