{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/on-the-robustness-of-semantic-segmentation","title":"On the Robustness of Semantic Segmentation Models to Adversarial Attacks","arxiv_id":"1711.09856","date":"2017-11-27","proceeding":"CVPR 2018 6","authors":["Anurag Arnab","Ondrej Miksik","Philip H. S. Torr"],"abstract":"Deep Neural Networks (DNNs) have demonstrated exceptional performance on most\nrecognition tasks such as image classification and segmentation. However, they\nhave also been shown to be vulnerable to adversarial examples. This phenomenon\nhas recently attracted a lot of attention but it has not been extensively\nstudied on multiple, large-scale datasets and structured prediction tasks such\nas semantic segmentation which often require more specialised networks with\nadditional components such as CRFs, dilated convolutions, skip-connections and\nmultiscale processing. In this paper, we present what to our knowledge is the\nfirst rigorous evaluation of adversarial attacks on modern semantic\nsegmentation models, using two large-scale datasets. We analyse the effect of\ndifferent network architectures, model capacity and multiscale processing, and\nshow that many observations made on the task of classification do not always\ntransfer to this more complex task. Furthermore, we show how mean-field\ninference in deep structured models, multiscale processing (and more generally,\ninput transformations) naturally implement recently proposed adversarial\ndefenses. Our observations will aid future efforts in understanding and\ndefending against adversarial examples. Moreover, in the shorter term, we show\nhow to effectively benchmark robustness and show which segmentation models\nshould currently be preferred in safety-critical applications due to their\ninherent robustness.","url_abs":"http://arxiv.org/abs/1711.09856v3","url_pdf":"http://arxiv.org/pdf/1711.09856v3.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"on-the-robustness-of-semantic-segmentation","repo_url":"https://github.com/hmph/adversarial-attacks","is_official":1,"mentioned_in_paper":0,"mentioned_in_github":0,"framework":"caffe2","reach":{"status":"unanswered"}}],"tasks":[{"task_slug":"classification","task_name":"General Classification"},{"task_slug":"image-classification","task_name":"Image Classification"},{"task_slug":"segmentation","task_name":"Segmentation"},{"task_slug":"semantic-segmentation","task_name":"Semantic Segmentation"},{"task_slug":"structured-prediction","task_name":"Structured Prediction"},{"task_slug":"image-classification","task_name":"image-classification"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":"https://syntology.ai/paper/1711.09856","atlas_url":"https://app.syntology.ai/?focus=1711.09856","mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}