日本フィジカルAI新聞

世界のフィジカルAIを、日本語で。

週刊ニュースレター購読
敵対的攻撃arXiv:2605.18058

アラビア語手書き文字認識への脅威:組み込みConvNetモデルに対するブラックボックス敵対的攻撃の調査

Threats to Arabic Handwriting Recognition: Investigating Black-Box Adversarial Attacks on embedded ConvNet models

シェア:XThreadsFacebookLINEはてブBluesky

アラビア語手書き文字認識モデルがブラックボックス敵対的攻撃に対して脆弱であることを実証し、特にPixle攻撃が高い成功率を示すことを明らかにした。

著者: Mohsine EL Khayati, Abdelillah Semma, Abdelaziz Courr, Rachid Elouahbi

分類: cs.CV

原文アブストラクト

Arabic handwriting recognition (AHR) has made significant progress with deep learning models. AHR research has largely focused on performance, with security receiving little attention. This study provides what appears to be a new line of inquiry by demonstrating the vulnerability of high-performing models to adversarial black-box attacks. The focus on black-box attacks reflects real-world scenarios where the attacker has no prior knowledge of the model architecture. Extensive experiments were conducted on two benchmark AHR datasets containing Arabic handwritten Characters. Results demonstrated the effectiveness of the attacks, with the Pixle attack achieving an attack success rate of 99-100\% on most models. Other, less aggressive attacks achieved success rates of 50-96\% across most experiments. Despite the higher attack success rate, the attacks maintain the structural integrity of the characters, rendering them almost imperceptible to the human eye. The findings indicate the higher vulnerability of the studied models to adversarial manipulation. This underscores the need to strengthen efforts to secure these models and ensure their reliability in AHR real-world applications.

関連論文