返回
Average Gradient-Based Adversarial Attack
DOI:10.1109/TMM.2023.3255742.png)
摘要
En 中文
Deep neural networks (DNNs) are vulnerable to adversarial attacks which can fool the classifiers by adding small perturbations to the original example. The added perturbations in most existing attacks are mainly determined by the gradient of the loss function with respect to the current example. In this paper, a new average gradient-based adversarial attack is proposed. In our proposed method, via utilizing the gradient of each iteration in the past, a dynamic set of adversarial examples is constructed first in each iteration. Then, according to the gradient of the loss function with respect to all the examples in the constructed dynamic set and the current adversarial example, the average gradient can be calculated, which is used to determine the added perturbations. Different from the existing adversarial attacks, the proposed average gradient-based attack optimizes the added perturbations through a dynamic set of adversarial examples, where the size of the dynamic set increases with the number of iterations. Our proposed method possesses good extensibility and can be integrated into most existing gradient-based attacks. Extensive experiments demonstrate that, compared with the state-of-the-art gradient-based adversarial attacks, the proposed attack can achieve higher attack success rates and exhibit better transferability, which is helpful to evaluate the robustness of the network and the effectiveness of the defense method.
Keyword:
Adversarial attack
black-box attack
dynamic set of adversarial examples
transferability
期刊
IF:
9.7
论文数:
4.5K
被引数:
2.4W
机构
引用论文
A novel and efficient xanthenic dye–organometallic ion‐pair complex for photoinitiating polymerization一种用于光引发聚合的新型高效的黄原胶染料-有机金属离子对配合物
Welding characteristics of aluminum, copper, nickel and aluminum alloy with alumina coating using ultrasonic complex vibration welding equipments铝、铜、镍及铝合金氧化铝涂层超声复合振动焊接特性研究

