Related Experiment Videos
Vulnerability analysis of transformer-based optical character recognition to adversarial attacks
Lucas Beerens1, Desmond J Higham1
1The University of Edinburgh , Edinburgh, UK.
Summary
State-of-the-art transformer-based optical character recognition (TrOCR) models exhibit significant vulnerabilities to adversarial attacks. Even imperceptible input perturbations can drastically compromise TrOCR model performance and security.
Area of Science:
- Artificial Intelligence
- Computer Vision
- Machine Learning Security
Background:
- Transformer-based optical character recognition (TrOCR) models are advanced AI systems.
- Assessing the robustness of these models is crucial for their safe deployment in critical applications.
Purpose of the Study:
- To introduce a novel framework for evaluating the resilience of TrOCR models.
- To develop and test new adversarial attack algorithms against TrOCR systems.
Main Methods:
- Development of untargeted and targeted adversarial attack algorithms.
- Evaluation of attack efficacy on a benchmark handwriting dataset.
- Analysis of the impact of subtle input perturbations on model output.
Main Results:
- Adversarial perturbations were found to cause dramatic vulnerabilities in TrOCR models.
- These perturbations were visually imperceptible to human observers.
- The study highlights significant security weaknesses in current TrOCR technology.
Conclusions:
- TrOCR models are susceptible to sophisticated adversarial attacks.
- Robustness assessments are essential for AI safety in critical systems.
- Further research is needed to enhance the security of optical character recognition AI.