arrow
Return

A multi-objective memetic algorithm for automatic adversarial attack optimization design

delete2023-08-01
delete3
PRE
AI
J
Jialiang Sun
W
Wen Yao *
T
Tingsong Jiang
X
Xiaoqian Chen
DOI:10.1016/j.neucom.2023.126318delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
The phenomenon of adversarial examples has been revealed in variant scenarios. Recent studies show that well-designed adversarial defense strategies can improve the robustness of deep learning models against adversarial examples. However, with the rapid development of defense technologies, it also tends to be more difficult to evaluate the robustness of the defensed model due to the weak performance of existing manually designed adversarial attacks. To address the challenge, given the defensed model, the efficient adversarial attack with less computational burden and lower robust accuracy is needed to be further exploited. Therefore, we propose a multi-objective memetic algorithm for auto adversarial attack optimization design, which realizes the automatic search for the near-optimal adversarial attack towards defensed models. Firstly, the more general mathematical model of auto adversarial attack opti-mization design is constructed, where the search space includes not only the attacker operations, mag-nitude, iteration number, and loss functions but also the connection ways of multiple adversarial attacks. In addition, we develop a multi-objective memetic algorithm combining NSGA-II and local search to solve the optimization problem. Finally, to decrease the evaluation cost during the search, we propose a representative data selection strategy based on sorting cross entropy loss values of images output by models. Experiments on CIFAR10, CIFAR100, and ImageNet datasets show that our method can efficiently find near-optimal adversarial attacks with lower robust accuracy and less time cost, which can provide more reliable and efficient robustness evaluation for defensed models.& COPY; 2023 Elsevier B.V. All rights reserved.
Keywords:
Adversarial attack
Adversarial defense
Robustness evaluation
Multi -objective optimization
Memetic algorithm

Journal

Neurocomputing cover
Neurocomputing
IF:
6.5
Papers:
2.5W
Citations:
6.5W

Organization

No organization information available