arrow
返回

Push & Pull: Transferable Adversarial Examples With Attentive Attack

delete2022-01-01
delete28
PRE
AI
L
Lianli Gao
Z
Zijie Huang
Jingkuan Song 封面图
Jingkuan Song (Jingkuan Song) *
杨
杨阳 (Yang Yang)
申恒涛 封面图
申恒涛 (Heng Tao Shen)
DOI:10.1109/TMM.2021.3079723delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Targeted attack aims to mislead the classification model to a specific class, and it can be further divided into black-box and white-box targeted attack depending on whether the classification model is known. A growing number of approaches rely on disrupting the image representations to craft adversarial examples. However, this type of methods often suffer from either low white-box targeted attack success rate or poor black-box targeted attack transferability. To address these problems, we propose a Transferable Attentive Attack (TAA) method which adds perturbation to clean images based on the attended regions and features. This is motivated by one important observation that deep-learning based classification models (or even shallow-learning based models like SIFT) make the prediction mainly based on the informative and discriminative regions of an image. Specifically, the corresponding features of the informative regions are firstly extracted, and the anchor image's features are iteratively pushed away from the source class and simultaneously pulled closer to the target class along with attacking. Moreover, we introduce a new strategy that the attack selects the centroids of source and target class cluster as the input of triplet loss to achieve high transferability. Experimental results demonstrate that our method improves the transferability of adversarial example, while maintaining higher success rate for white-box targeted attacks compared with the state-of-the-arts. In particular, TAA attacks on image-representation based task like VQA also result in a significant performance drop in terms of accuracy.
Keyword:
Perturbation methods
Feature extraction
Computational modeling
Task analysis
Predictive models
Neural networks
Iterative methods
Image classification
adversarial attack
transferability
targeted attack
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

IEEE Transactions on Multimedia 封面图
IEEE Transactions on Multimedia
IF:
9.7
论文数:
4.5K
被引数:
2.4W

机构

暂无机构信息
引用论文

引用论文

err
IF0
err
err0
PREAI
err
err分享
err收藏
err分享
err收藏
A Fast Optimization Method for General Binary Code Learning
err2016-12-01
err135
PREAI
errShen, Fumin; Zhou, Xiang; Yang, Yang; Song, Jingkuan; Shen, Heng Tao; Tao, Dacheng
err分享
err收藏
学者 查看更多内容