arrow
Return

Boosting cross-task adversarial attack with random blur

delete2022-05-24
delete5
delete
OA
AI
Y
Yaoyuan Zhang
Y
Yu‐an Tan
鲁溟峰 cover
鲁溟峰 (Ming-Feng Lu)
T
Tian Chen
李元章 cover
李元章 (Yuanzhang Li)
张全新 cover
张全新 (Quanxin Zhang) *
DOI:10.1002/int.22932delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Deep neural networks are highly vulnerable to adversarial examples, and these adversarial examples stay malicious when transferred to other neural networks. Many works exploit this transferability of adversarial examples to execute black-box attacks. However, most existing adversarial attack methods rarely consider cross-task black-box attacks that are more similar to real-world scenarios. In this paper, we propose a class of random blur-based iterative methods (RBMs) to enhance the success rates of cross-task black-box attacks. By integrating the random erasing and Gaussian blur into the iterative gradient-based attacks, the proposed RBM augments the diversity of adversarial perturbation and alleviates the marginal effect caused by iterative gradient-based methods, generating the adversarial examples of stronger transferability. Experimental results on ImageNet and PASCAL VOC data sets show that the proposed RBM generates more transferable adversarial examples on image classification models, thereby successfully attacking cross-task black-box object detection models.
Keywords:
adversarial examples
deep neural networks
image classification
object detection
transferability

Journal

International Journal of Intelligent Systems cover
International Journal of Intelligent Systems
IF:
3.7
Papers:
3.0K
Citations:
8.1K

Organization

B
beijing institute of technology
Scholars:
5.4W
Papers: 4.0W
Citations: 63