Skip to main content

Showing 1–6 of 6 results for author: Jere, M

Searching in archive cs. Search in all archives.
.
  1. arXiv:2206.04783  [pdf, other

    cs.CV cs.CR cs.LG

    ReFace: Real-time Adversarial Attacks on Face Recognition Systems

    Authors: Shehzeen Hussain, Todd Huster, Chris Mesterharm, Paarth Neekhara, Kevin An, Malhar Jere, Harshvardhan Sikka, Farinaz Koushanfar

    Abstract: Deep neural network based face recognition models have been shown to be vulnerable to adversarial examples. However, many of the past attacks require the adversary to solve an input-dependent optimization problem using gradient descent which makes the attack impractical in real-time. These adversarial examples are also tightly coupled to the attacked model and are not as successful in transferring… ▽ More

    Submitted 9 June, 2022; originally announced June 2022.

  2. Adversarial Scratches: Deployable Attacks to CNN Classifiers

    Authors: Loris Giulivi, Malhar Jere, Loris Rossi, Farinaz Koushanfar, Gabriela Ciocarlie, Briland Hitaj, Giacomo Boracchi

    Abstract: A growing body of work has shown that deep neural networks are susceptible to adversarial examples. These take the form of small perturbations applied to the model's input which lead to incorrect predictions. Unfortunately, most literature focuses on visually imperceivable perturbations to be applied to digital images that often are, by design, impossible to be deployed to physical targets. We pre… ▽ More

    Submitted 18 May, 2023; v1 submitted 20 April, 2022; originally announced April 2022.

    Comments: This work is published at Pattern Recognition (Elsevier). This paper stems from 'Scratch that! An Evolution-based Adversarial Attack against Neural Networks' for which an arXiv preprint is available at arXiv:1912.02316. Further studies led to a complete overhaul of the work, resulting in this paper

    ACM Class: I.4; I.5

    Journal ref: Pattern Recognition, Volume 133, January 2023, 108985

  3. arXiv:2012.03516  [pdf, other

    cs.CV

    A Singular Value Perspective on Model Robustness

    Authors: Malhar Jere, Maghav Kumar, Farinaz Koushanfar

    Abstract: Convolutional Neural Networks (CNNs) have made significant progress on several computer vision benchmarks, but are fraught with numerous non-human biases such as vulnerability to adversarial samples. Their lack of explainability makes identification and rectification of these biases difficult, and understanding their generalization behavior remains an open problem. In this work we explore the rela… ▽ More

    Submitted 7 December, 2020; originally announced December 2020.

  4. arXiv:2002.12749  [pdf, other

    cs.CV

    Adversarial Deepfakes: Evaluating Vulnerability of Deepfake Detectors to Adversarial Examples

    Authors: Shehzeen Hussain, Paarth Neekhara, Malhar Jere, Farinaz Koushanfar, Julian McAuley

    Abstract: Recent advances in video manipulation techniques have made the generation of fake videos more accessible than ever before. Manipulated videos can fuel disinformation and reduce trust in media. Therefore detection of fake videos has garnered immense interest in academia and industry. Recently developed Deepfake detection methods rely on deep neural networks (DNNs) to distinguish AI-generated fake v… ▽ More

    Submitted 7 November, 2020; v1 submitted 9 February, 2020; originally announced February 2020.

    Comments: Published as a conference paper at WACV 2021

  5. arXiv:1912.03406  [pdf, other

    cs.LG cs.CV eess.IV stat.ML

    Principal Component Properties of Adversarial Samples

    Authors: Malhar Jere, Sandro Herbig, Christine Lind, Farinaz Koushanfar

    Abstract: Deep Neural Networks for image classification have been found to be vulnerable to adversarial samples, which consist of sub-perceptual noise added to a benign image that can easily fool trained neural networks, posing a significant risk to their commercial deployment. In this work, we analyze adversarial samples through the lens of their contributions to the principal components of each image, whi… ▽ More

    Submitted 6 December, 2019; originally announced December 2019.

  6. arXiv:1912.02316  [pdf, other

    cs.NE cs.LG eess.IV

    Scratch that! An Evolution-based Adversarial Attack against Neural Networks

    Authors: Malhar Jere, Loris Rossi, Briland Hitaj, Gabriela Ciocarlie, Giacomo Boracchi, Farinaz Koushanfar

    Abstract: We study black-box adversarial attacks for image classifiers in a constrained threat model, where adversaries can only modify a small fraction of pixels in the form of scratches on an image. We show that it is possible for adversaries to generate localized \textit{adversarial scratches} that cover less than $5\%$ of the pixels in an image and achieve targeted success rates of $98.77\%$ and… ▽ More

    Submitted 6 August, 2020; v1 submitted 4 December, 2019; originally announced December 2019.