arrow
Return

Learning relationship-preserving representation for multi-task adversarial attacks

delete2023-10-01
delete0
PRE
AI
Y
Yong Chen
X
Xu Wang
胡鹏 (Peng Hu)
Y
Yuan Zhong
D
Dezhong Peng
Q
Qilin Li *
DOI:10.1016/j.neucom.2023.126580delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Deep neural networks (DNNs) are susceptible to adversarial samples that are carefully crafted to mislead the DNNs with imperceptible perturbations. To test the robustness of DNNs, attack methods based on adversarial samples have gained popularity due to their practicality and effectiveness in achieving encouraging attack results. However, most of these methods do not consider the more realistic multi-task attacks. The main challenge of multi-task attacks is that different tasks have different objective functions, making it difficult to find an optimal optimization goal to generate adversarial samples. To address this issue, we propose a new multi-task adversarial attack paradigm called Multi-Task Adversarial Attacks (MTAA) that uses a relationship preserving representation to learn adversarial patterns. Unlike previous methods, our attack method does not rely on a task-specific loss function or an attack agent model. Instead, we design a relationship-preserving module that projects samples into a low-dimensional embedding space while preserving their intrinsic geometric structure for adversarial pattern reasoning. This module effectively removes redundant information from high-dimensional features, providing an effective latent space for adversarial pattern reasoning. To learn adversarial representation in the latent space, we introduce a novel adversarial mechanism. Our attack method can deceive different networks on multiple tasks since it is independent of task-specific loss functions and the attack agent. Extensive experimental results show that our attack approach outperforms state-of-theart universal and transferable attack strategies on multi-task attacks. The codes for MTAA are available at https://github.com/antachen/MTAA.
Keywords:
Multi-task attack
Adversarial sample
Relationship-preserving representation

Journal

Neurocomputing cover
Neurocomputing
IF:
6.5
Papers:
2.5W
Citations:
6.5W

Organization

S
State Grid Corporation of China
Scholars:
6.5K
Papers: 5.2K
Citations: 1.7K
S
sichuan university
Scholars:
12.0W
Papers: 7.7W
Citations: 100