The machine learning community has seen an explosion in the sophistication of adversarial attacks against deep neural network-based computer vision models. In particular, researchers have successfully used adversarial patterns to trigger false positive or false negative results in both research and real-world settings. However, researchers have not yet codified performance metrics for evaluating the efficacy of attack techniques. This evaluation is needed to adequately assess performance improvements of novel adversarial attack methods. This study aims to contribute the following: adversarial pattern performance metrics, demonstration of each metric’s strengths and contributions on a case study, and an initial standardized performance evaluation strategy for novel adversarial pattern attacks. We train state-of-the-art deep neural network-based object detection models on an open-source dataset. We then use these trained models to evaluate trained adversarial patterns for both false positive and false negative attacks and evaluate their performance using our suite of metrics in order to establish and codify a workflow to be used when evaluating future adversarial pattern algorithms.
Access to the requested content is limited to institutions that have purchased or subscribe to SPIE eBooks.
You are receiving this notice because your organization may not have SPIE eBooks access.*
*Shibboleth/Open Athens users─please
sign in
to access your institution's subscriptions.
To obtain this item, you may purchase the complete book in print or electronic format on
SPIE.org.
INSTITUTIONAL Select your institution to access the SPIE Digital Library.
PERSONAL Sign in with your SPIE account to access your personal subscriptions or to use specific features such as save to my library, sign up for alerts, save searches, etc.