Skip to main content
Journal cover image

Attacking Sequential Learning Models with Style Transfer Based Adversarial Examples

Publication ,  Conference
Zhang, Z; Yang, X; Huang, K
Published in: Journal of Physics: Conference Series
April 27, 2021

In the field of deep neural network security, it has been recently found that non-sequential networks are vulnerable to adversarial examples. There are however few studies to investigate the adversarial attack on sequential tasks. To this end, in this paper, we propose a novel method to generate adversarial examples for sequential tasks. Specifically, an image style transfer method is used to generate for a Scene Text Recognition (STR) network adversarial examples, which are only different from the original image on the style. While they will not interfere with the recognition of image information by human vision, the adversarial examples would significantly mislead the recognition results of sequential networks. Moreover, based on a black-box attack, both in digital and physical environments, we show that the proposed method can use cross text shape information and attack successfully the TPS-ResNet-BiLSTM-Attention (TRBA) and Convolutional Recurrent Neural Network (CRNN) models. Finally, we demonstrate further that physical adversarial examples can easily mislead commercial recognition algorithms, e.g. iFLYTEK and Youdao, suggesting that STR models are also highly vulnerable to attacks from adversarial examples.

Duke Scholars

Published In

Journal of Physics: Conference Series

DOI

EISSN

1742-6596

ISSN

1742-6588

Publication Date

April 27, 2021

Volume

1880

Issue

1

Related Subject Headings

  • 0299 Other Physical Sciences
  • 0204 Condensed Matter Physics
  • 0202 Atomic, Molecular, Nuclear, Particle and Plasma Physics
 

Citation

APA
Chicago
ICMJE
MLA
NLM
Zhang, Z., Yang, X., & Huang, K. (2021). Attacking Sequential Learning Models with Style Transfer Based Adversarial Examples. In Journal of Physics: Conference Series (Vol. 1880). https://doi.org/10.1088/1742-6596/1880/1/012021
Zhang, Z., X. Yang, and K. Huang. “Attacking Sequential Learning Models with Style Transfer Based Adversarial Examples.” In Journal of Physics: Conference Series, Vol. 1880, 2021. https://doi.org/10.1088/1742-6596/1880/1/012021.
Zhang Z, Yang X, Huang K. Attacking Sequential Learning Models with Style Transfer Based Adversarial Examples. In: Journal of Physics: Conference Series. 2021.
Zhang, Z., et al. “Attacking Sequential Learning Models with Style Transfer Based Adversarial Examples.” Journal of Physics: Conference Series, vol. 1880, no. 1, 2021. Scopus, doi:10.1088/1742-6596/1880/1/012021.
Zhang Z, Yang X, Huang K. Attacking Sequential Learning Models with Style Transfer Based Adversarial Examples. Journal of Physics: Conference Series. 2021.
Journal cover image

Published In

Journal of Physics: Conference Series

DOI

EISSN

1742-6596

ISSN

1742-6588

Publication Date

April 27, 2021

Volume

1880

Issue

1

Related Subject Headings

  • 0299 Other Physical Sciences
  • 0204 Condensed Matter Physics
  • 0202 Atomic, Molecular, Nuclear, Particle and Plasma Physics