返回
ELAA: An efficient local adversarial attack using model interpreters
DOI:10.1002/int.22680.png)
摘要
En 中文
Modern deep neural networks are highly vulnerable to adversarial examples, which attracts more and more researchers' attention to craft powerful adversarial examples. Most of these generation algorithms create global perturbations that would affect the visual quality of adversarial examples. To mitigate such drawbacks, some attacks attempt to generate local perturbations. However, existing local adversarial attacks are time-consuming and the generated adversarial examples are still distinguishable from clean images. In this paper, we propose a novel efficient local adversarial attack (ELAA) using model interpreters to generate severe local perturbations and improve the imperceptibly of the generated adversarial examples. Specifically, we take advantage of model interpretation methods to search the discriminative regions of clean images. Then, we generate local adversarial examples by adding masks to original clean images. We also propose a new optimization method to reduce the redundancy of local perturbations. Through extensive experiments, we show our ELAA can maintain a high attack ability while preserving the visual quality of clean images. Experimental results also demonstrate our local attack outperforms state-of-the-art local attack methods under various system settings.
Keyword:
adversarial example
local attack
machine learning interpreter
saliency map
期刊
IF:
3.7
论文数:
3.1K
被引数:
8.1K
机构
引用论文
Intercellular Adhesion Molecule 1 (ICAM-1) Gene Variant is Associated with Coronary Artery Calcification Independent of Soluble ICAM-1 Levels细胞间粘附分子1 (ICAM-1) 基因变异与冠状动脉钙化相关,与可溶性ICAM-1水平无关
Welding characteristics of aluminum, copper, nickel and aluminum alloy with alumina coating using ultrasonic complex vibration welding equipments铝、铜、镍及铝合金氧化铝涂层超声复合振动焊接特性研究
Enhanced Reactivity of Dinuclear Copper(I) Acetylides in Dipolar Cycloadditions偶极环加成反应中双核乙炔铜 (I) 的反应性增强

