Skip to main content

Research Repository

Advanced Search

One-Index Vector Quantization Based Adversarial Attack on Image Classification

Fan, Haiju; Qin, Xiaona; Chen, Shuang; Li, Ming; Shum, Hubert P. H.

Authors

Haiju Fan

Xiaona Qin

Profile Image

Chris Chen shuang.chen@durham.ac.uk
Summer School Academic (Casual)

Ming Li



Abstract

To improve storage and transmission, images are generally compressed. Vector quantization (VQ) is a popular compression method as it has a high compression ratio that suppresses other compression techniques. Despite this, existing adversarial attack methods on image classification are mostly performed in the pixel domain with few exceptions in the compressed domain, making them less applicable in real-world scenarios. In this paper, we propose a novel one-index attack method in the VQ domain to generate adversarial images by a differential evolution algorithm, successfully resulting in image misclassification in victim models. The one-index attack method modifies a single index in the compressed data stream so that the decompressed image is misclassified. It only needs to modify a single VQ index to realize an attack, which limits the number of perturbed indexes. The proposed method belongs to a semi-black-box attack, which is more in line with the actual attack scenario. We apply our method to attack three popular image classification models, i.e., Resnet, NIN, and VGG16. On average, 55.9% and 77.4% of the images in CIFAR-10 and Fashion MNIST, respectively, are successfully attacked, with a high level of misclassification confidence and a low level of image perturbation.

Citation

Fan, H., Qin, X., Chen, S., Li, M., & Shum, H. P. H. (in press). One-Index Vector Quantization Based Adversarial Attack on Image Classification. Pattern Recognition Letters,

Journal Article Type Article
Acceptance Date Sep 2, 2024
Deposit Date Sep 3, 2024
Journal Pattern Recognition Letters
Print ISSN 0167-8655
Electronic ISSN 1872-7344
Publisher Elsevier
Peer Reviewed Peer Reviewed
Public URL https://durham-repository.worktribe.com/output/2783616
Publisher URL https://www.sciencedirect.com/journal/pattern-recognition-letters

This file is under embargo due to copyright reasons.




You might also like



Downloadable Citations