返回
Image classification adversarial attack with improved resizing transformation and ensemble models
DOI:10.7717/peerj-cs.1475.png)
摘要
En 中文
Convolutional neural networks have achieved great success in computer vision, but incorrect predictions would be output when applying intended perturbations on original input. These human-indistinguishable replicas are called adversarial examples, which on this feature can be used to evaluate network robustness and security. White-box attack success rate is considerable, when already knowing network structure and parameters. But in a black-box attack, the adversarial examples success rate is relatively low and the transferability remains to be improved. This article refers to model augmentation which is derived from data augmentation in training generalizable neural networks, and proposes resizing invariance method. The proposed method introduces improved resizing transformation to achieve model augmentation. In addition, ensemble models are used to generate more transferable adversarial examples. Extensive experiments verify the better performance of this method in comparison to other baseline methods including the original model augmentation method, and the black-box attack success rate is improved on both the normal models and defense models.
Keyword:
Computer graphics
Adversarial examples
Image classification
Convolutional neural networks
Image transformation
Improved resizing
Transferability
Ensemble models
AI总结
对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。
期刊
IF:
2.5
论文数:
3.4K
被引数:
6.9K
机构
引用论文
First definitive observations of meteor shower particles using a high-power large-aperture radar
Icarus
IF0
Deep Transfer Learning for Land Use and Land Cover Classification: A Comparative Study土地利用和土地覆盖分类的深度迁移学习: 一项比较研究
SENSORS
IF3.5

