arrow
返回

An efficient adversarial example generation algorithm based on an accelerated gradient iterative fast gradient

delete2022-08-01
delete25
PRE
AI
刘
刘家保 (Jia‐Bao Liu)
Q
Qixiang Zhang
K
Kanghua Mo
X
Xiaoyu Xiang
J
Jin Li
D
Debin Cheng *
R
Rui Gao
B
Beishui Liu
K
Kongyang Chen
G
Guanjie Wei
DOI:10.1016/j.csi.2021.103612delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Most existing deep neural networks are susceptible to the influence of adversarial examples, which may cause them to output incorrect prediction results. An adversarial example is the addition of small noise disturbances to the input data samples, which will deceive the classification. Generally, these modifications are very small noise disturbances, which are not easily noticed by the human eye. However, most existing adversarial attacks achieve only low success rates in typical black-box settings, where the attackers have no prior knowledge about the model structures and/or model parameters. To tackle this problem, we propose an iterative algorithm based on an acceleration gradient to enhance the adversary attack. Our method accumulates the gradient of the loss function in each iteration and uses the next gradient information to influence the future gradient. We also introduce the scaling invariance principle of a deep neural network to optimize the input images for black-box attacks. In addition, to handle the drawbacks of a traditional iterative fast gradient sign method, we further present two gradient optimization methods. Experimental results on the ImageNet dataset show that our attack methods can achieve good transferability. In addition, those models obtained by integrated adversarial training with strong defense capability are also quite vulnerable to our black-box attack.
Keyword:
Iterative fast gradient
Adversarial examples
Transferable

期刊

C
Computer Standards and Interfaces
IF:
3.1
论文数:
2.3K
被引数:
2.0K

机构

G
Guangzhou University
学者数:
1.8W
论文数: 1.3W
被引数: 1.8W
引用论文

引用论文

err分享
err收藏
Adversarial attacks on deep-learning-based SAR image target recognition
err2020-07-01
err86
PREAI
errHuang, Teng; Zhang, Qixiang; Liu, Jiabao; Hou, Ruitao; Wang, Xianmin; Li, Ya
err分享
err收藏
Defense against adversarial attacks by low-level image transformations
err2020-07-20
err22
errOAAI
errYin, Zhaoxia; Wang, Hua; Wang, Jie; Tang, Jin; Wang, Wenzhong
err分享
err收藏
Privacy preservation of electronic health records with adversarial attacks identification in hybrid cloud
err2021-10-01
err15
PREAI
errKanwal, Tehsin; Anjum, Adeel; Malik, Saif U. R.; Khan, Abid; Khan, Muazzam A.
err分享
err收藏
学者 查看更多内容