{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/characterizing-and-evaluating-adversarial","title":"Characterizing and evaluating adversarial examples for Offline Handwritten Signature Verification","arxiv_id":"1901.03398","date":"2019-01-10","proceeding":null,"authors":["Luiz G. Hafemann","Robert Sabourin","Luiz S. Oliveira"],"abstract":"The phenomenon of Adversarial Examples is attracting increasing interest from\nthe Machine Learning community, due to its significant impact to the security\nof Machine Learning systems. Adversarial examples are similar (from a\nperceptual notion of similarity) to samples from the data distribution, that\n\"fool\" a machine learning classifier. For computer vision applications, these\nare images with carefully crafted but almost imperceptible changes, that are\nmisclassified. In this work, we characterize this phenomenon under an existing\ntaxonomy of threats to biometric systems, in particular identifying new attacks\nfor Offline Handwritten Signature Verification systems. We conducted an\nextensive set of experiments on four widely used datasets: MCYT-75, CEDAR,\nGPDS-160 and the Brazilian PUC-PR, considering both a CNN-based system and a\nsystem using a handcrafted feature extractor (CLBP). We found that attacks that\naim to get a genuine signature rejected are easy to generate, even in a limited\nknowledge scenario, where the attacker does not have access to the trained\nclassifier nor the signatures used for training. Attacks that get a forgery to\nbe accepted are harder to produce, and often require a higher level of noise -\nin most cases, no longer \"imperceptible\" as previous findings in object\nrecognition. We also evaluated the impact of two countermeasures on the success\nrate of the attacks and the amount of noise required for generating successful\nattacks.","url_abs":"http://arxiv.org/abs/1901.03398v1","url_pdf":"http://arxiv.org/pdf/1901.03398v1.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"characterizing-and-evaluating-adversarial","repo_url":"https://github.com/luizgh/adversarial_signatures","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":1,"framework":"pytorch","reach":{"status":"unanswered"}},{"paper_slug":"characterizing-and-evaluating-adversarial","repo_url":"https://github.com/luizgh/sigver","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"pytorch","reach":{"status":"unanswered"}}],"tasks":[{"task_slug":"machine-learning","task_name":"BIG-bench Machine Learning"},{"task_slug":"object-recognition","task_name":"Object Recognition"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":"https://syntology.ai/paper/1901.03398","atlas_url":"https://app.syntology.ai/?focus=1901.03398","mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}