The widespread adoption of deep learning (DL) models raises concerns about their trustworthiness and reliability. Adversarial attacks are cyber-related attacks that target the DL network's prediction by adding imperceptible perturbations to its input. Their deployment against critical artificial-intelligence-based systems, such as industrial cyber–physical systems (ICPSs), can result in substantial damage. Research on their scope and limitations can provide information that would help with their detection and prevention. In this article, the interconnection of adversarial attacks and interpretable semantic segmentation is investigated for potential applications in the ICPS in order to contribute to the safe use of future intelligent systems. We first explore gradient-based interpretability extensions to semantic segmentation on two industry-related cyber–physical system datasets. Then, two types of attacks on semantic segmentation networks are discussed. First, we apply the dense adversary generation attack on different segmentation outputs and evaluate its influence on the corresponding saliency maps. We then introduce a way to visualize the similarity of attacked saliency maps to the original with respect to the targeted attack's direction. Finally, we extend the application of adversarial attacks on saliency maps to semantic segmentation.

The Impact of Adversarial Attacks on Interpretable Semantic Segmentation in Cyber–Physical Systems / Gipiskis, R.; Chiaro, D.; Preziosi, M.; Prezioso, E.; Piccialli, F.. - In: IEEE SYSTEMS JOURNAL. - ISSN 1932-8184. - (2023), pp. 1-8. [10.1109/JSYST.2023.3281079]

The Impact of Adversarial Attacks on Interpretable Semantic Segmentation in Cyber–Physical Systems

Chiaro D.;Prezioso E.;Piccialli F.
2023

Abstract

The widespread adoption of deep learning (DL) models raises concerns about their trustworthiness and reliability. Adversarial attacks are cyber-related attacks that target the DL network's prediction by adding imperceptible perturbations to its input. Their deployment against critical artificial-intelligence-based systems, such as industrial cyber–physical systems (ICPSs), can result in substantial damage. Research on their scope and limitations can provide information that would help with their detection and prevention. In this article, the interconnection of adversarial attacks and interpretable semantic segmentation is investigated for potential applications in the ICPS in order to contribute to the safe use of future intelligent systems. We first explore gradient-based interpretability extensions to semantic segmentation on two industry-related cyber–physical system datasets. Then, two types of attacks on semantic segmentation networks are discussed. First, we apply the dense adversary generation attack on different segmentation outputs and evaluate its influence on the corresponding saliency maps. We then introduce a way to visualize the similarity of attacked saliency maps to the original with respect to the targeted attack's direction. Finally, we extend the application of adversarial attacks on saliency maps to semantic segmentation.
2023
The Impact of Adversarial Attacks on Interpretable Semantic Segmentation in Cyber–Physical Systems / Gipiskis, R.; Chiaro, D.; Preziosi, M.; Prezioso, E.; Piccialli, F.. - In: IEEE SYSTEMS JOURNAL. - ISSN 1932-8184. - (2023), pp. 1-8. [10.1109/JSYST.2023.3281079]
File in questo prodotto:
Non ci sono file associati a questo prodotto.

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11588/953469
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 9
  • ???jsp.display-item.citation.isi??? 5
social impact