Papers
Topics
Authors
Recent
Search
2000 character limit reached

A White-Box False Positive Adversarial Attack Method on Contrastive Loss Based Offline Handwritten Signature Verification Models

Published 17 Aug 2023 in cs.CV, cs.AI, cs.CR, and cs.LG | (2308.08925v3)

Abstract: In this paper, we tackle the challenge of white-box false positive adversarial attacks on contrastive loss based offline handwritten signature verification models. We propose a novel attack method that treats the attack as a style transfer between closely related but distinct writing styles. To guide the generation of deceptive images, we introduce two new loss functions that enhance the attack success rate by perturbing the Euclidean distance between the embedding vectors of the original and synthesized samples, while ensuring minimal perturbations by reducing the difference between the generated image and the original image. Our method demonstrates state-of-the-art performance in white-box attacks on contrastive loss based offline handwritten signature verification models, as evidenced by our experiments. The key contributions of this paper include a novel false positive attack method, two new loss functions, effective style transfer in handwriting styles, and superior performance in white-box false positive attacks compared to other white-box attack methods.

Definition Search Book Streamline Icon: https://streamlinehq.com
References (33)
  1. Threat of adversarial attacks on deep learning in computer vision: A survey. IEEE Access, 6:14410–14430.
  2. Writer-independent signature verification; evaluation of robotic and generative adversarial attacks. Information Sciences, 633:170–181.
  3. Towards evaluating the robustness of neural networks. In 2017 IEEE Symposium on Security and Privacy (SP), pages 39–57. Ieee.
  4. Signet: Convolutional siamese network for writer independent offline signature verification. arXiv preprint arXiv:1707.02131.
  5. Boosting adversarial attacks with momentum. In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR), pages 9185–9193.
  6. A neural algorithm of artistic style. arXiv preprint arXiv:1508.06576.
  7. Explaining and harnessing adversarial examples. In International Conference on Learning Representations (ICLR).
  8. A siamese transformer network for zero-shot ancient coin classification. Journal of Imaging, 9(6):107.
  9. Artwork protection against neural style transfer using locally adaptive adversarial color attack. arXiv preprint arXiv:2401.09673.
  10. Dimensionality reduction by learning an invariant mapping. In 2006 IEEE Computer Society Conference on Computer Vision and Pattern Recognition (CVPR), volume 2, pages 1735–1742. IEEE.
  11. Writer-independent feature learning for offline signature verification using deep convolutional neural networks. In 2016 International Joint Conference on Neural Networks (IJCNN), pages 2576–2583. IEEE.
  12. Characterizing and evaluating adversarial examples for offline handwritten signature verification. IEEE Transactions on Information Forensics and Security, 14(8):2153–2166.
  13. Perceptual losses for real-time style transfer and super-resolution. In Computer Vision–ECCV 2016: 14th European Conference, Amsterdam, The Netherlands, October 11-14, 2016, Proceedings, Part II 14, pages 694–711. Springer.
  14. Adam: A method for stochastic optimization. In International Conference on Learning Representations (ICLR).
  15. Adversarial examples in the physical world. In Artificial Intelligence Safety and Security, pages 99–112. Chapman and Hall/CRC.
  16. Interpolated joint space adversarial training for robust and generalizable defenses. IEEE Transactions on Pattern Analysis and Machine Intelligence.
  17. Black-box attack against handwritten signature verification with region-restricted adversarial perturbations. Pattern Recognition, 111:107689.
  18. Adversarial training for the adversarial robustness of eeg-based brain-computer interfaces. In 2022 IEEE 32nd International Workshop on Machine Learning for Signal Processing (MLSP), pages 1–6. IEEE.
  19. Mutual adversarial training: Learning together is better than going alone. IEEE Transactions on Information Forensics and Security, 17:2364–2377.
  20. Segment and complete: Defending object detectors against adversarial patch attacks with robust patch detection. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR), pages 14973–14982.
  21. Towards deep learning models resistant to adversarial attacks. In International Conference on Learning Representations (ICLR).
  22. Transferability in machine learning: from phenomena to black-box attacks using adversarial samples. arXiv preprint arXiv:1605.07277.
  23. Signature embedding: Writer independent offline signature verification with deep metric learning. In Advances in Visual Computing: 12th International Symposium, ISVC 2016, Las Vegas, NV, USA, December 12-14, 2016, Proceedings, Part II 12, pages 616–625. Springer.
  24. 2c2s: A two-channel and two-stream transformer based framework for offline signature verification. Engineering Applications of Artificial Intelligence, 118:105639.
  25. Intriguing properties of neural networks. In International Conference on Learning Representations (ICLR).
  26. Enhancing the transferability of adversarial attacks through variance tuning. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR), pages 1924–1933.
  27. Leaky dnn: Stealing deep-learning model secret with gpu context-switching side-channel. In 2020 50th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN), pages 125–137. IEEE.
  28. Yılmaz, M. B. (2015). Offline signature verification with user-based and global classifiers of local features. PhD thesis, Sabancı University.
  29. Two strategies to optimize the decisions in signature verification with the presence of spoofing attacks. Information Sciences, 352:188–202.
  30. Improving adversarial robustness by learning shared information. Pattern Recognition, 134:109054.
  31. Stealing neural network structure through remote fpga side-channel analysis. IEEE Transactions on Information Forensics and Security, 16:4377–4388.
  32. Prompt as triggers for backdoor attack: Examining the vulnerability in language models. In Proceedings of the 2023 Conference on Empirical Methods in Natural Language Processing, pages 12303–12317.
  33. Unpaired image-to-image translation using cycle-consistent adversarial networks. In Proceedings of the IEEE International Conference on Computer Vision (ICCV), pages 2223–2232.
Citations (10)

Summary

No one has generated a summary of this paper yet.

Paper to Video (Beta)

No one has generated a video about this paper yet.

Whiteboard

No one has generated a whiteboard explanation for this paper yet.

Open Problems

We haven't generated a list of open problems mentioned in this paper yet.

Continue Learning

We haven't generated follow-up questions for this paper yet.

Collections

Sign up for free to add this paper to one or more collections.