arrow
返回

Adversarial examples generated from sample subspace

delete2022-08-01
delete1
PRE
AI
X
Xiaozhang Liu
L
Lang Li
X
Xueyang Wang *
L
Li Hu
DOI:10.1016/j.csi.2022.103634delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Attacks and defenses have been a hot issue in the field of deep learning. Because of the vulnerability of deep learning models, it is easy to attack them by adversarial examples. Adversarial examples are carefully added perturbations to fool the deep learning model. For such samples, humans are able to classify correctly, while deep learning models are prone to give a high confidence false output. The working mechanism of adversarial samples has always been a difficult point and focus of research. In this work, the nature of the attack from the adversarial samples is studied accordingly from the perspective of the main and minor features of PCA (principal component analysis). Firstly, we find that the deep learning model mainly learns the main features of the data, rather than the minor features. Secondly, we discover that perturbations on the main features are more likely to lead to misclassification of the deep learning model, while perturbations on the minor features have little effect. Finally, we propose a method to generate adversarial samples in the sample subspace. Experimental results on both MNIST and CIFAR10 show that the proposed method generates smaller adversarial sample perturbations, which are more difficult to detect by human eyes and more aggressive against white-box attacks on deep learning models.
Keyword:
Adversarial examples
PCA
Defense
Deep learning

期刊

C
Computer Standards and Interfaces
IF:
3.1
论文数:
2.3K
被引数:
2.0K

机构

G
Guangzhou University
学者数:
1.8W
论文数: 1.3W
被引数: 1.8W
H
Hainan University
学者数:
2.0W
论文数: 1.2W
被引数: 1.9W
引用论文

引用论文

First crown ether derivative of benzoxazinone; a new fluoroionophore for alkaline earth metals recognition
err1988-01-01
err0
PREAI
errSuzanne Fery-Forgues; Marie-Thérèse Le Bris; Jean-Paul Guetté; Bernard Valeur
err分享
err收藏
Efficient machine learning over encrypted data with non-interactive communication
err2018-05-01
err24
PREAI
errPark, Heejin; Kim, Pyung; Kim, Heeyoul; Park, Ki-Woong; Lee, Younho
err分享
err收藏
err分享
err收藏
Three-dimensional feature maps and convolutional neural network-based emotion recognition
err2021-06-29
err33
errOAAI
errZheng, Xiangwei; Yu, Xiaomei; Yin, Yongqiang; Li, Tiantian; Yan, Xiaoyan
err分享
err收藏
Vehicle model recognition from frontal view image measurements
err2011-02-01
err108
PREAI
errPsyllos, A.; Anagnostopoulos, C. N.; Kayafas, E.
err分享
err收藏
err分享
err收藏
Privacy preservation of electronic health records with adversarial attacks identification in hybrid cloud
err2021-10-01
err15
PREAI
errKanwal, Tehsin; Anjum, Adeel; Malik, Saif U. R.; Khan, Abid; Khan, Muazzam A.
err分享
err收藏
学者 查看更多内容