arrow
Return

Revisiting ensemble adversarial attack

delete2022-09-01
delete7
PRE
AI
Z
Ziwen He
王维 (Wei Wang) *
J
Jing Dong
T
Tieniu Tan
DOI:10.1016/j.image.2022.116747delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Deep neural networks have shown vulnerability to adversarial attacks. Adversarial examples generated with an ensemble of source models can effectively attack unseen target models, posing a security threat to practical applications. In this paper, we investigate the manner of ensemble adversarial attacks from the viewpoint of network gradients with respect to inputs. We observe that most ensemble adversarial attacks simply average gradients of the source models, ignoring their different contributions in the ensemble. To remedy this problem, we propose two novel ensemble strategies, the Magnitude-Agnostic Bagging Ensemble (MABE) strategy and Gradient-Grouped Bagging And Stacking Ensemble (G2BASE) strategy. The former builds on a bagging ensemble and leverages a gradient normalization module to rebalance the ensemble weights. The latter divides diverse models into different groups according to the gradient magnitudes and combines an intragroup bagging ensemble with an intergroup stacking ensemble. Experimental results show that the proposed methods enhance the success rate in white-box attacks and further boost the transferability in black-box attacks.
Keywords:
Adversarial attack
Ensemble strategies
Gradient-based methods
Deep neural networks
Image classification

Journal

S
Signal Processing and Image Communication
IF:
2.7
Papers:
2.8K
Citations:
4.2K

Organization

C
chinese academy of sciences
Scholars:
56.1W
Papers: 44.8W
Citations: 704