arrow
Return

Frequency domain regularization for iterative adversarial attacks

delete2023-02-01
delete6
PRE
AI
T
Tengjiao Li
M
Maosen Li
Y
Yanhua Yang *
邓
邓程 (Cheng Deng)
DOI:10.1016/j.patcog.2022.109075delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Adversarial examples have attracted more and more attentions with the prosperity of convolutional neural networks. The transferability of adversarial examples is an important property that makes black-box attacks possible in real-world applications. On the other side, many adversarial defense methods have been proposed to improve the robustness, leading to the requirement for more transferable adversarial examples. Inspired by the regularization term for network parameters at training process, we treat adversarial attacks as training process of inputs and propose regularization constraint for inputs to prevent adversarial examples from overfitting the white-box networks and enhance the transferability. Specifically, we find a universal attribute that the outputs of convolutional neural networks have consistency to the low frequencies of inputs, and based on this, we construct a frequency domain regularization to inputs for iterative attacks. In this way, our method is compatible with existing iterative attack methods and can learn more transferable adversarial examples. Extensive experiments on ImageNet validate the superiority of our method, and compared with several attacks, we achieve attack success rate improvements of 8.0% and 11.5% on average to normal models and defense methods respectively. (c) 2022 Published by Elsevier Ltd.
Keywords:
Adversarial examples
Transfer-based attack
Black-box attack
Frequency-domain characteristics

Journal

Pattern Recognition cover
Pattern Recognition
IF:
7.6
Papers:
1.3W
Citations:
4.5W

Organization

X
Xidian University
Scholars:
2.4W
Papers: 1.9W
Citations: 9.7K
Cited Papers

Cited Papers

Adaptive iterative attack towards explainable adversarial robustness
err2020-09-01
err45
PREAI
errShi, Yucheng; Han, Yahong; Zhang, Quanxin; Kuang, Xiaohui
errShare
errSave
On the vulnerability of face verification systems to hill-climbing attacks
err2010-03-01
err72
PREAI
errGalbally, Javier; McCool, Chris; Fierrez, Julian; Marcel, Sebastien; Ortega-Garcia, Javier
errShare
errSave
Deep image prior based defense against adversarial examples
err2022-02-01
err27
PREAI
errDai, Tao; Feng, Yan; Chen, Bin; Lu, Jian; Xia, Shu-Tao
errShare
errSave
Towards robust explanations for deep neural networks
err2022-01-01
err36
errOAAI
errDombrowski, Ann-Kathrin; Anders, Christopher J.; Mueller, Klaus-Robert; Kessel, Pan
errShare
errSave
Universal adversarial perturbations against object detection
err2021-02-01
err30
PREAI
errLi, Debang; Zhang, Junge; Huang, Kaiqi
errShare
errSave
A black-box adversarial attack strategy with adjustable sparsity and generalizability for deep image classifiers
err2022-02-01
err30
errOAAI
errGhosh, Arka; Mullick, Sankha Subhra; Datta, Shounak; Das, Swagatam; Das, Asit Kr; Mallipeddi, Rammohan
errShare
errSave
Ensemble adversarial black-box attacks against deep learning systems
err2020-05-01
err39
PREAI
errHang, Jie; Han, Keji; Chen, Hui; Li, Yun
errShare
errSave
no more