vix.ing · top · new · best · stats · spec

Light Lies: Optical Adversarial Attack

2021/06/18 by Kyu-Lim Kim, Kim, Kyulim, Jeong-Soo Kim +9 · 1 citation
Biochemistry, Genetics and Molecular Biology · Computer Science · Engineering · #Adversarial Robustness in Machine Learning #Computer Vision and Pattern Recognition (cs.CV) #FOS: Computer and information sciences #FOS: Electrical engineering #Image and Video Processing (eess.IV) #Integrated Circuits and Semiconductor Failure Analysis #Spectroscopy Techniques in Biomedical and Chemical Research #electronic engineering #information engineering

paper · pdf · doi:10.48550/arxiv.2106.09908

openalex publication_date 2021/06/18 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/28

Abstract

A significant amount of work has been done on adversarial attacks that inject imperceptible noise to images to deteriorate the image classification performance of deep models. However, most of the existing studies consider attacks in the digital (pixel) domain where an image acquired by an image sensor with sampling and quantization has been recorded. This paper, for the first time, introduces an optical adversarial attack, which physically alters the light field information arriving at the image sensor so that the classification model yields misclassification. More specifically, we modulate the phase of the light in the Fourier domain using a spatial light modulator placed in the photographic system. The operative parameters of the modulator are obtained by gradient-based optimization to maximize cross-entropy and minimize distortions. We present experiments based on both simulation and a real hardware optical system, from which the feasibility of the proposed optical attack is demonstrated. It is also verified that the proposed attack is completely different from common optical-domain distortions such as spherical aberration, defocus, and astigmatism in terms of both perturbation patterns and classification results.

Citations

Cited by

Related