Researchers Develop Technique to Manipulate AI Computer Vision Systems

Artificial intelligence (AI) computer vision systems have been crucial in various applications, including autonomous vehicles, health technologies, and security systems. However, researchers have discovered vulnerabilities in these systems, which can be exploited to control what the AI sees or does not see in an image. A new technique called RisingAttacK has been developed to manipulate all the most widely used AI computer vision systems, including ResNet-50, DenseNet-121, ViTB, and DEiT-B. This technique can be used to affect human health and safety in various contexts.

Key Takeaways:

  • RisingAttacK is a new technique that allows researchers to manipulate all the most widely used AI computer vision systems, including ResNet-50, DenseNet-121, ViTB, and DEiT-B.
  • The technique works by identifying all the visual features in an image, determining which features are most important to achieve the attack's goal, and calculating how sensitive the AI system is to changes in data.
  • RisingAttacK requires minimal computational power to make small, targeted changes to the key features that makes the attack successful.
  • The researchers tested RisingAttacK against the four most commonly used vision AI programs and found it was effective in manipulating all four programs.
  • The technique can influence the AI's ability to see any of the top 20 or 30 targets it was trained to identify, such as cars, pedestrians, or traffic signals.
  • The research team has made RisingAttacK publicly available for the research community to test neural networks for vulnerabilities.
  • The potential applications of this technique include autonomous vehicles, health technologies, and security systems.

Statistics:

  • The researchers tested RisingAttacK against the four most commonly used vision AI programs: ResNet-50, DenseNet-121, ViTB, and DEiT-B.
  • RisingAttacK requires the ability to influence the AI's ability to see any of the top 20 or 30 targets it was trained to identify.
  • The research was supported by the National Science Foundation under grants 1909644, 2024688, and 2013451, and from the Army Research Office under grants W911NF1810295 and W911NF2210010.

Sources:

  • VerticalNews Health, "Researchers Develop Technique to Manipulate AI Computer Vision Systems" (July 20, 2025)
  • International Conference of Machine Learning, "Adversarial Perturbations Are Formed by Iteratively Learning Linear Combinations of the Right Singular Vectors of the Adversarial Jacobian" (July 15, 2025)
  • National Science Foundation, Grants 1909644, 2024688, and 2013451
  • Army Research Office, Grants W911NF1810295 and W911NF2210010