错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Exploring Imperceptible Adversarial Examples in  \(YC_bC_r\) Color Space

  • Pei Chen,
  • Zhiyong Feng,
  • Meng Xing,
  • Yiming Zhang,
  • Jinqing Zheng

摘要

Numerous studies have shown that well-designed perturbations can easily fool deep neural networks. Existing attacks are mainly conducted on the low-level pixels of RGB images, resulting in noise-like perturbations distributed over the entire image, highly vulnerable and low attack transferability. Furthermore, they delve into the data space with point-wise perturbation, which may neglect the geometric characteristics and fail to study the role and impact of various image components. Compared with RGB images, \(YC_bC_r\) images can express various image components more intuitively. In this paper, we propose generating semantically preserved adversarial examples by perturbing the frequency band energy corresponding to inconspicuous colors and textures in the \(YC_bC_r\) color space. Specifically, we first transform clean images from spatial to frequency domain, followed by applying a fusion module to indirectly inject perturbations. Moreover, the low-frequency constraint and luma-chroma optimization strategy are further introduced to ensure visual imperceptibility. Extensive experiments on multiple datasets indicate that our attack retains a high attack success rate while significantly improving visual quality.