arrow
返回

Frequency domain regularization for iterative adversarial attacks

delete2023-02-01
delete6
PRE
AI
T
Tengjiao Li
M
Maosen Li
Y
Yanhua Yang *
邓
邓程 (Cheng Deng)
DOI:10.1016/j.patcog.2022.109075delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Adversarial examples have attracted more and more attentions with the prosperity of convolutional neural networks. The transferability of adversarial examples is an important property that makes black-box attacks possible in real-world applications. On the other side, many adversarial defense methods have been proposed to improve the robustness, leading to the requirement for more transferable adversarial examples. Inspired by the regularization term for network parameters at training process, we treat adversarial attacks as training process of inputs and propose regularization constraint for inputs to prevent adversarial examples from overfitting the white-box networks and enhance the transferability. Specifically, we find a universal attribute that the outputs of convolutional neural networks have consistency to the low frequencies of inputs, and based on this, we construct a frequency domain regularization to inputs for iterative attacks. In this way, our method is compatible with existing iterative attack methods and can learn more transferable adversarial examples. Extensive experiments on ImageNet validate the superiority of our method, and compared with several attacks, we achieve attack success rate improvements of 8.0% and 11.5% on average to normal models and defense methods respectively. (c) 2022 Published by Elsevier Ltd.
Keyword:
Adversarial examples
Transfer-based attack
Black-box attack
Frequency-domain characteristics

期刊

Pattern Recognition 封面图
Pattern Recognition
IF:
7.6
论文数:
1.3W
被引数:
4.5W

机构

X
Xidian University
学者数:
2.4W
论文数: 1.9W
被引数: 9.7K
引用论文

引用论文

Adaptive iterative attack towards explainable adversarial robustness
err2020-09-01
err45
PREAI
errShi, Yucheng; Han, Yahong; Zhang, Quanxin; Kuang, Xiaohui
err分享
err收藏
On the vulnerability of face verification systems to hill-climbing attacks
err2010-03-01
err72
PREAI
errGalbally, Javier; McCool, Chris; Fierrez, Julian; Marcel, Sebastien; Ortega-Garcia, Javier
err分享
err收藏
err分享
err收藏
Towards robust explanations for deep neural networks
err2022-01-01
err36
errOAAI
errDombrowski, Ann-Kathrin; Anders, Christopher J.; Mueller, Klaus-Robert; Kessel, Pan
err分享
err收藏
没有更多内容