A2SC: Adversarial Attack on Subspace Clustering

Yikun Xu,Xingxing Wei,Pengwen Dai,Xiaochun Cao
DOI: https://doi.org/10.1109/icme52920.2022.9859835
IF: 4.094
2023-01-01
ACM Transactions on Multimedia Computing Communications and Applications
Abstract:Many studies demonstrate supervised learning techniques are vulnerable to adversarial examples. However, adversarial threats in unsupervised learning have not drawn sufficient scholarly attention. In this paper, we formally address the unexplored adversarial attacks in the equally, if not more, important unsupervised clustering field and propose the concept of adversarial set. To illustrate the basic idea, we design an exemplary adversarial space-mapping attack algorithm to confuse subspace clustering, one of the mainstream branches of unsupervised clustering. It maps a sample into one wrong class by moving it towards the closest point on the linear subspace of the target class, i.e. along the normal of the closest point. The simple single-step algorithm is powerful to craft the adversarial set where the samples can be wrongly clustered, even into targeted labels. The adversarial set has the merit of transferability among subspace clustering schemes. Empirical results verify the effectiveness and transferability of our algorithm.
What problem does this paper attempt to address?