arrow
返回

Boosting adversarial attacks with transformed gradient

delete2022-07-01
delete12
PRE
AI
Z
Zhengyun He
Y
Yexin Duan
W
Wu Zhang
J
Junhua Zou
Z
Zhengfang He
Y
Yunyun Wang
Z
Zhisong Pan *
DOI:10.1016/j.cose.2022.102720delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Deep neural networks (DNNs) are vulnerable to adversarial examples, which are crafted by adding imperceptible perturbations to benign examples. Increasing the attack success rate usually requires a larger noise magnitude, which leads to noticeable noise. To this end, we propose a Transformed Gradient method (TG), which achieves a higher attack success rate with lower perturbations against the target model, i.e. an ensemble of black-box defense models. It consists of three steps: original gradient accumulation, gradient amplification, and gradient truncation. Besides, we introduce the Fr e ' chet Inception Distance (FID) and Learned Perceptual Image Patch Similarity (LPIPS) respectively to evaluate fidelity and perceived distance from the original example, which is more comprehensive than only using L infinity norm as evaluation metrics. Furthermore, we propose optimizing coefficients of the source-model ensemble to improve adversarial attacks. Extensive experimental results demonstrate that the perturbations of adversarial examples generated by our proposed method are less than the state-of-the-art baselines, namely MI, DI, TI, RF-DE based on vanilla iterative FGSM and their combinations. Compared with the baseline method, the average black-box attack success rate and total score are improved by 6.6% and 13.8, respectively. We make our codes public at Github https://github.com/Hezhengyun/Transformed-Gradient . (c) 2022 Elsevier Ltd. All rights reserved.
Keyword:
Deep neural networks
Image classification
Adversarial examples
Adversarial machine learning
Adversarial attack
Transferability

期刊

C
Computers and Security
IF:
5.4
论文数:
4.6K
被引数:
1.4W

机构

A
Army Engineering University of PLA
学者数:
5.0K
论文数: 3.7K
被引数: 5