arrow
Return

SingleADV: Single-Class Target-Specific Attack Against Interpretable Deep Learning Systems

delete2024-01-01
delete0
PRE
AI
E
Eldor Abdukhamidov
M
Mohammed Abuhamad
G
George K. Thiruvathukal
H
Hyoungshick Kim
T
Tamer Abuhmed *
DOI:10.1109/TIFS.2024.3407652delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Establishing trust and helping experts debug and understand the inner workings of deep learning models, interpretation methods are increasingly coupled with these models, building interpretable deep learning systems. However, adversarial attacks pose a significant threat to public trust by making interpretations of deep learning models confusing and difficult to understand. In this paper, we present a novel Single-class target-specific ADVersarial attack called SingleADV. The goal of SingleADV is to generate a universal perturbation that deceives the target model into confusing a specific category of objects with a target category while ensuring highly relevant and accurate interpretations. The universal perturbation is stochastically and iteratively optimized by minimizing the adversarial loss that is designed to consider both the classifier and interpreter costs in targeted and non-targeted categories. In this optimization framework, ruled by the first- and second-moment estimations, the desired loss surface promotes high confidence and interpretation scores of adversarial samples. By avoiding unintended misclassification of samples from other categories, SingleADV enables more effective targeted attacks on interpretable deep learning systems in both white-box and black-box scenarios. To evaluate the effectiveness of SingleADV, we conduct experiments using four different model architectures (ResNet-50, VGG-16, DenseNet-169, and Inception-V3) coupled with three interpretation models (CAM, Grad, and MASK). Through extensive empirical evaluation, we demonstrate that SingleADV effectively deceives target deep learning models and their associated interpreters under various conditions and settings. Our results show that the performance of SingleADV is effective, with an average attack success rate of 74% and prediction confidence exceeding 77% on successful adversarial samples. Furthermore, we discuss several countermeasures against SingleADV, including a transfer-based learning approach and existing preprocessing defenses.
Keywords:
Perturbation methods
Deep learning
Predictive models
Glass box
Closed box
Computational modeling
Data models
Convolutional neural networks
interpretation models
adversarial attack
adversarial perturbation
images

Journal

IEEE Transactions on Information Forensics and Security cover
IEEE Transactions on Information Forensics and Security
IF:
8
Papers:
5.2K
Citations:
2.3W

Organization

L
Loyola University Chicago
Scholars:
8.0K
Papers: 6.0K
Citations: 5.8K
S
sungkyunkwan university (skku)
Scholars:
3.7W
Papers: 3.6W
Citations: 49