Universal Watermark Attack in Image Classification
Shaokang Wu · 2021 International Conference on Intelligent Computing, Automation and Systems (ICICAS) · 2021
Recent researches have shown it is possible to fool a deep neural network classifier by adding watermark perturbations. The watermark can be used to protect copyright and has practical meaning, but currently, there is no method that can generate universal watermark perturbation. The main reason is that the fooling rate is no differentiable for the perturbations. In this paper, we adopt the loss function trick and mask function trick to generate universal watermark perturbation then evaluate its fooling rate with different watermark shapes, locations, numbers and deep neural network architectures. The results show the universal watermark perturbations achieve good performance and can be successfully used to generate universal watermark adversarial examples.