Skip to main content

Showing 1–2 of 2 results for author: Finnie, N

Searching in archive cs. Search in all archives.
.
  1. arXiv:2203.13639  [pdf, other

    cs.CV

    Give Me Your Attention: Dot-Product Attention Considered Harmful for Adversarial Patch Robustness

    Authors: Giulio Lovisotto, Nicole Finnie, Mauricio Munoz, Chaithanya Kumar Mummadi, Jan Hendrik Metzen

    Abstract: Neural architectures based on attention such as vision transformers are revolutionizing image recognition. Their main benefit is that attention allows reasoning about all parts of a scene jointly. In this paper, we show how the global reasoning of (scaled) dot-product attention can be the source of a major vulnerability when confronted with adversarial patch attacks. We provide a theoretical under… ▽ More

    Submitted 25 March, 2022; originally announced March 2022.

    Comments: to be published in IEEE/CVF Conference on Computer Vision and Pattern Recognition 2022, CVPR22

    MSC Class: 68T07 ACM Class: I.4

  2. arXiv:2101.11453  [pdf, other

    cs.LG cs.AI cs.CV stat.ML

    Meta Adversarial Training against Universal Patches

    Authors: Jan Hendrik Metzen, Nicole Finnie, Robin Hutmacher

    Abstract: Recently demonstrated physical-world adversarial attacks have exposed vulnerabilities in perception systems that pose severe risks for safety-critical applications such as autonomous driving. These attacks place adversarial artifacts in the physical world that indirectly cause the addition of a universal patch to inputs of a model that can fool it in a variety of contexts. Adversarial training is… ▽ More

    Submitted 22 June, 2021; v1 submitted 27 January, 2021; originally announced January 2021.

    Comments: Accepted by the ICML 2021 workshop on "A Blessing in Disguise: The Prospects and Perils of Adversarial Machine Learning"