Skip to main navigation Skip to search Skip to main content

Adversarial attacks on multi-focus image fusion models

  • Xin Jin*
  • , Ruxin Wang
  • , Shin Jye Lee
  • , Qian Jiang
  • , Shaowen Yao
  • , Wei Zhou
  • *Corresponding author for this work

Research output: Contribution to journalArticlepeer-review

4 Scopus citations

Abstract

Multi-focus image fusion aims to create an all-in-focus clear image by fusing a set of partially focused images. In recent years, various multi-focus image fusion methods based on deep learning have been proposed, but there is no thorough study evaluating their robustness for adversarial attacks. In this paper, we investigate the robustness of deep learning based multi-focus image fusion models to adversarial attacks. First, we generated adversarial examples which can significantly reduce the fusion quality of image fusion models. Then, a metric defocus attack intensity (DAI) was proposed to quantitatively evaluate the robustness of different models for adversarial attacks. At last, we analyzed the factors affecting model robustness, including model size and post-processing steps. Besides, we successfully attacked recent image fusion models in the black-box scene by utilizing the transferability of adversarial examples. Experimental results show that state-of-the-art image fusion models are also vulnerable to adversarial attacks, and some observations in image classifier robustness studies are not transferable to image fusion task.

Original languageEnglish
Article number103455
JournalComputers and Security
Volume134
DOIs
StatePublished - Nov 2023

Keywords

  • Adversarial attack
  • Deep learning
  • Image processing
  • Multi-focus image fusion
  • Neural networks

Fingerprint

Dive into the research topics of 'Adversarial attacks on multi-focus image fusion models'. Together they form a unique fingerprint.

Cite this