arrow
Return

Adversarial examples generated from sample subspace

delete2022-08-01
delete1
PRE
AI
X
Xiaozhang Liu
L
Lang Li
X
Xueyang Wang *
L
Li Hu
DOI:10.1016/j.csi.2022.103634delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Attacks and defenses have been a hot issue in the field of deep learning. Because of the vulnerability of deep learning models, it is easy to attack them by adversarial examples. Adversarial examples are carefully added perturbations to fool the deep learning model. For such samples, humans are able to classify correctly, while deep learning models are prone to give a high confidence false output. The working mechanism of adversarial samples has always been a difficult point and focus of research. In this work, the nature of the attack from the adversarial samples is studied accordingly from the perspective of the main and minor features of PCA (principal component analysis). Firstly, we find that the deep learning model mainly learns the main features of the data, rather than the minor features. Secondly, we discover that perturbations on the main features are more likely to lead to misclassification of the deep learning model, while perturbations on the minor features have little effect. Finally, we propose a method to generate adversarial samples in the sample subspace. Experimental results on both MNIST and CIFAR10 show that the proposed method generates smaller adversarial sample perturbations, which are more difficult to detect by human eyes and more aggressive against white-box attacks on deep learning models.
Keywords:
Adversarial examples
PCA
Defense
Deep learning

Journal

C
Computer Standards and Interfaces
IF:
3.1
Papers:
2.3K
Citations:
2.0K

Organization

G
Guangzhou University
Scholars:
1.8W
Papers: 1.3W
Citations: 1.8W
H
Hainan University
Scholars:
2.0W
Papers: 1.2W
Citations: 1.9W
Cited Papers

Cited Papers

First crown ether derivative of benzoxazinone; a new fluoroionophore for alkaline earth metals recognition
err1988-01-01
err0
PREAI
errSuzanne Fery-Forgues; Marie-Thérèse Le Bris; Jean-Paul Guetté; Bernard Valeur
errShare
errSave
Efficient machine learning over encrypted data with non-interactive communication
err2018-05-01
err24
PREAI
errPark, Heejin; Kim, Pyung; Kim, Heeyoul; Park, Ki-Woong; Lee, Younho
errShare
errSave
Adversarial perturbation in remote sensing image recognition
err2021-07-01
err26
PREAI
errAi, Shan; Koe, Arthur Sandor Voundi; Huang, Teng
errShare
errSave
Three-dimensional feature maps and convolutional neural network-based emotion recognition
err2021-06-29
err33
errOAAI
errZheng, Xiangwei; Yu, Xiaomei; Yin, Yongqiang; Li, Tiantian; Yan, Xiaoyan
errShare
errSave
Vehicle model recognition from frontal view image measurements
err2011-02-01
err108
PREAI
errPsyllos, A.; Anagnostopoulos, C. N.; Kayafas, E.
errShare
errSave
CSRT rumor spreading model based on complex network
err2021-01-11
err67
errOAAI
errAi, Shan; Hong, Sheng; Zheng, Xinyang; Wang, Yue; Liu, Xiaozhang
errShare
errSave
errShare
errSave
Privacy preservation of electronic health records with adversarial attacks identification in hybrid cloud
err2021-10-01
err15
PREAI
errKanwal, Tehsin; Anjum, Adeel; Malik, Saif U. R.; Khan, Abid; Khan, Muazzam A.
errShare
errSave
researcher View more