Beyond Pixel Norm-Balls: Parametric Adversaries using an Analytically Differentiable Renderer

Many machine learning image classifiers are vulnerable to adversarial\nattacks, inputs with perturbations designed to intentionally trigger\nmisclassification. Current adversarial methods directly alter pixel colors and\nevaluate against pixel norm-balls: pixel perturbations smaller than a specified\nmagnitude, according to a measurement norm. This evaluation, however, has\nlimited practical utility since perturbations in the pixel space do not\ncorrespond to underlying real-world phenomena of image formation that lead to\nthem and has no security motivation attached. Pixels in natural images are\nmeasurements of light that has interacted with the geometry of a physical\nscene. As such, we propose the direct perturbation of physical parameters that\nunderly image formation: lighting and geometry. As such, we propose a novel\nevaluation measure, parametric norm-balls, by directly perturbing physical\nparameters that underly image formation. One enabling contribution we present\nis a physically-based differentiable renderer that allows us to propagate pixel\ngradients to the parametric space of lighting and geometry. Our approach\nenables physically-based adversarial attacks, and our differentiable renderer\nleverages models from the interactive rendering literature to balance the\nperformance and accuracy trade-offs necessary for a memory-efficient and\nscalable adversarial data augmentation workflow.\n

Paper

Similar papers

© 2026 NYSGPT2525 LLC