arrow
返回

Average Gradient-Based Adversarial Attack

delete2023-01-01
delete14
PRE
AI
C
Chen Wan
F
Fangjun Huang *
赵
赵险峰 (Xianfeng Zhao)
DOI:10.1109/TMM.2023.3255742delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Deep neural networks (DNNs) are vulnerable to adversarial attacks which can fool the classifiers by adding small perturbations to the original example. The added perturbations in most existing attacks are mainly determined by the gradient of the loss function with respect to the current example. In this paper, a new average gradient-based adversarial attack is proposed. In our proposed method, via utilizing the gradient of each iteration in the past, a dynamic set of adversarial examples is constructed first in each iteration. Then, according to the gradient of the loss function with respect to all the examples in the constructed dynamic set and the current adversarial example, the average gradient can be calculated, which is used to determine the added perturbations. Different from the existing adversarial attacks, the proposed average gradient-based attack optimizes the added perturbations through a dynamic set of adversarial examples, where the size of the dynamic set increases with the number of iterations. Our proposed method possesses good extensibility and can be integrated into most existing gradient-based attacks. Extensive experiments demonstrate that, compared with the state-of-the-art gradient-based adversarial attacks, the proposed attack can achieve higher attack success rates and exhibit better transferability, which is helpful to evaluate the robustness of the network and the effectiveness of the defense method.
Keyword:
Adversarial attack
black-box attack
dynamic set of adversarial examples
transferability

期刊

IEEE Transactions on Multimedia 封面图
IEEE Transactions on Multimedia
IF:
9.7
论文数:
4.5K
被引数:
2.4W

机构

S
Sun Yat Sen University
学者数:
9.9W
论文数: 7.2W
被引数: 95
C
chinese academy of sciences
学者数:
56.7W
论文数: 45.0W
被引数: 704
引用论文

引用论文

Image Super-Resolution as a Defense Against Adversarial Attacks
err2020-01-01
err97
errOAAI
errMustafa, Aamir; Khan, Salman H.; Hayat, Munawar; Shen, Jianbing; Shao, Ling
err分享
err收藏
err分享
err收藏
学者 查看更多内容