English

CapsAttacks: Robust and Imperceptible Adversarial Attacks on Capsule Networks

Machine Learning 2019-05-27 v2 Cryptography and Security Computer Vision and Pattern Recognition Image and Video Processing Machine Learning

Abstract

Capsule Networks preserve the hierarchical spatial relationships between objects, and thereby bears a potential to surpass the performance of traditional Convolutional Neural Networks (CNNs) in performing tasks like image classification. A large body of work has explored adversarial examples for CNNs, but their effectiveness on Capsule Networks has not yet been well studied. In our work, we perform an analysis to study the vulnerabilities in Capsule Networks to adversarial attacks. These perturbations, added to the test inputs, are small and imperceptible to humans, but can fool the network to mispredict. We propose a greedy algorithm to automatically generate targeted imperceptible adversarial examples in a black-box attack scenario. We show that this kind of attacks, when applied to the German Traffic Sign Recognition Benchmark (GTSRB), mislead Capsule Networks. Moreover, we apply the same kind of adversarial attacks to a 5-layer CNN and a 9-layer CNN, and analyze the outcome, compared to the Capsule Networks to study differences in their behavior.

Keywords

Cite

@article{arxiv.1901.09878,
  title  = {CapsAttacks: Robust and Imperceptible Adversarial Attacks on Capsule Networks},
  author = {Alberto Marchisio and Giorgio Nanfa and Faiq Khalid and Muhammad Abdullah Hanif and Maurizio Martina and Muhammad Shafique},
  journal= {arXiv preprint arXiv:1901.09878},
  year   = {2019}
}
R2 v1 2026-06-23T07:24:31.304Z