Color Channel Perturbation Attacks for Fooling Convolutional Neural Networks and A Defense Against Such Attacks
The Convolutional Neural Networks (CNNs) have emerged as a very powerful data\ndependent hierarchical feature extraction method. It is widely used in several\ncomputer vision problems. The CNNs learn the important visual features from\ntraining samples automatically. It is observed that the network overfits the\ntraining samples very easily. Several regularization methods have been proposed\nto avoid the overfitting. In spite of this, the network is sensitive to the\ncolor distribution within the images which is ignored by the existing\napproaches. In this paper, we discover the color robustness problem of CNN by\nproposing a Color Channel Perturbation (CCP) attack to fool the CNNs. In CCP\nattack new images are generated with new channels created by combining the\noriginal channels with the stochastic weights. Experiments were carried out\nover widely used CIFAR10, Caltech256 and TinyImageNet datasets in the image\nclassification framework. The VGG, ResNet and DenseNet models are used to test\nthe impact of the proposed attack. It is observed that the performance of the\nCNNs degrades drastically under the proposed CCP attack. Result show the effect\nof the proposed simple CCP attack over the robustness of the CNN trained model.\nThe results are also compared with existing CNN fooling approaches to evaluate\nthe accuracy drop. We also propose a primary defense mechanism to this problem\nby augmenting the training dataset with the proposed CCP attack. The\nstate-of-the-art performance using the proposed solution in terms of the CNN\nrobustness under CCP attack is observed in the experiments. The code is made\npublicly available at\n\\url{https://github.com/jayendrakantipudi/Color-Channel-Perturbation-Attack}.\n
Paper
References (58)
Scroll for more · 38 remaining