Return
A Second-Order Optimization-Based Adaptive Attack Method for Deep Convolutional Neural Networks
DOI:10.1109/TR.2025.3600691.png)
Abstract
En 中文
Deep convolutional neural networks (DCNNs) are vulnerable to small perturbations. Currently, first-order optimization-based adversarial attack methods are the mainstream methods for generating perturbations, such as PGD. It is known that, the second-order optimization method can converge faster than the first-order methods. Therefore, it is natural to expect the performance of second-order optimization-based attack methods should be better than that of first-order methods. However, the existing second-order attack methods do not demonstrate superior performance compared to first-order attack methods. The reason behind is that, these second-order attack methods employ the same sign function as first-order methods to generate pixel perturbations. Hence, in this article, we propose a second-order optimization-based adaptive attack method, and at its core, an adaptive perturbation generation strategy is designed. We evaluate the proposed method on multiple datasets and various models. The experimental results demonstrate that the proposed second-order optimization-based adaptive attack method is able to generate adversarial examples that cause misclassification of DCNNs in fewer iterations than existing second-order attack methods and PGD, and has competitive time complexity.
Keywords:
Adaptive perturbation generation
adversarial attacks
deep neural networks (DCNNs)
robustness
second-order optimization
Journal
IF:
5.7
Papers:
2.7K
Citations:
8.5K

