Return
One-pixel and X-pixel adversarial attacks based on smell bees optimization algorithm
DOI:10.1016/j.future.2023.07.028.png)
Abstract
En 中文
In the present paper, we propose two new black-box attacks to generate adversarial images. The first proposition is a new version One-pixel attack. It consists at reducing the search space of pixels by segmenting the image at the first stage. Then, a nature-inspired algorithm is applied to find the optimal pixel able to modify the decision of the deep learning model. The second proposition is X-pixel attack introduced to overcome the drawbacks of the One-pixel attack. It consists at firstly construct a large sub-set of potential pixels, then at apply a feature selection approach to optimize it. Many experiments are undertaken with CNN and ResNet learning models on MNIST and CIFAR-10 datasets. Some comparisons are also done with FGSM, PGD and JSMA attacks.& COPY; 2023 Elsevier B.V. All rights reserved.
Keywords:
Generation of adversarial examples
Deep neural networks
Nature-inspired algorithm
Journal
F
IF:
6.1
Papers:
6.8K
Citations:
2.3W

