arXiv Computer Vision

Adversarial Attacks and Identity Leakage in De-Identification Systems: An Empirical Study

arXiv AI
3d ago

Let the Carrier Carry the Attack: Preserving the Subject in Adversarial Image Generation

The paper introduces a "carrier"—a secondary visual element—to help preserve the main subject of an image during strong, unrestricted adversarial attacks. By allocating a larger portion of globally normalized attack updates to the carrier, the method reduces distortion of the subject while maintaining attack strength. Additionally, the carrier enhances cross-model transferability and allows targeted attacks to mislead classifiers while keeping the subject recognizable to humans.

By Linfeng Jiang, Steven McDonagh, Yuhang Chen, Xingyu Zhao, Siddartha Khastgir, Andi Zhang