arrow
Return

An efficient adversarial example generation algorithm based on an accelerated gradient iterative fast gradient

delete2022-08-01
delete25
PRE
AI
刘
刘家保 (Jia‐Bao Liu)
Q
Qixiang Zhang
K
Kanghua Mo
X
Xiaoyu Xiang
J
Jin Li
D
Debin Cheng *
R
Rui Gao
B
Beishui Liu
K
Kongyang Chen
G
Guanjie Wei
DOI:10.1016/j.csi.2021.103612delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Most existing deep neural networks are susceptible to the influence of adversarial examples, which may cause them to output incorrect prediction results. An adversarial example is the addition of small noise disturbances to the input data samples, which will deceive the classification. Generally, these modifications are very small noise disturbances, which are not easily noticed by the human eye. However, most existing adversarial attacks achieve only low success rates in typical black-box settings, where the attackers have no prior knowledge about the model structures and/or model parameters. To tackle this problem, we propose an iterative algorithm based on an acceleration gradient to enhance the adversary attack. Our method accumulates the gradient of the loss function in each iteration and uses the next gradient information to influence the future gradient. We also introduce the scaling invariance principle of a deep neural network to optimize the input images for black-box attacks. In addition, to handle the drawbacks of a traditional iterative fast gradient sign method, we further present two gradient optimization methods. Experimental results on the ImageNet dataset show that our attack methods can achieve good transferability. In addition, those models obtained by integrated adversarial training with strong defense capability are also quite vulnerable to our black-box attack.
Keywords:
Iterative fast gradient
Adversarial examples
Transferable

Journal

C
Computer Standards and Interfaces
IF:
3.1
Papers:
2.3K
Citations:
2.0K

Organization

G
Guangzhou University
Scholars:
1.8W
Papers: 1.3W
Citations: 1.8W
Cited Papers

Cited Papers

ImageNet Classification with Deep Convolutional Neural Networks
err2017-05-24
err8.3W
errOAAI
errKrizhevsky, Alex; Sutskever, Ilya; Hinton, Geoffrey E.
errShare
errSave
Adversarial attacks on deep-learning-based SAR image target recognition
err2020-07-01
err86
PREAI
errHuang, Teng; Zhang, Qixiang; Liu, Jiabao; Hou, Ruitao; Wang, Xianmin; Li, Ya
errShare
errSave
Defense against adversarial attacks by low-level image transformations
err2020-07-20
err22
errOAAI
errYin, Zhaoxia; Wang, Hua; Wang, Jie; Tang, Jin; Wang, Wenzhong
errShare
errSave
An adversarial attack on DNN-based black-box object detectors
err2020-07-01
err36
PREAI
errWang, Yajie; Tan, Yu-an; Zhang, Wenjiao; Zhao, Yuhang; Kuang, Xiaohui
errShare
errSave
Privacy preservation of electronic health records with adversarial attacks identification in hybrid cloud
err2021-10-01
err15
PREAI
errKanwal, Tehsin; Anjum, Adeel; Malik, Saif U. R.; Khan, Abid; Khan, Muazzam A.
errShare
errSave
researcher View more