conference-paper

Robust Attack with Adaptive Compress Adversarial Perturbations

  • 2021 International Conference on Computer Engineering and Application (ICCEA)
Research footprint

At a glance

الاستشهادات
0
المراجع
25
Comments
0
Paper overview

Abstract

Adversarial examples expose the vulnerability of deep neural networks that perform well in various fields. However, adversarial perturbations crafted by the existing attack methods are often aimed at the whole image. They are usually random, and the human eye can even easily perceive some of them. This paper proposes an adaptive method to compress the adversarial perturbation. Under the premise of ensuring the success of attacks, generating perturbations as small as possible to change the decision of classifiers. First, the authors find the minimum point of loss function by the optimization method, to expand the spanning space of adversarial examples. Calculating and selecting the smaller perturbation between this point and the original input. Then, in order to retain the useful perturbation and remove redundancy, the authors look for important regions in the input data that determine the network predict results, and construct an importance mask for the smaller perturbation of the previous stage. Extensive experiments on the ImageNet dataset and multiple network classifiers show that our method is effective. Compared with advanced attack methods, the $\mathbf{L}_{2}$ distance of adversarial perturbation obtained by our method is smaller and more practical, and the generated adversarial examples have strong transferability.

Record transparency

Publication details

DOI
10.1109/iccea53728.2021.00071
OpenAlex
W3208128163
Document type
conference-paper
Language
EN
Source
2021 International Conference on Computer Engineering and Application (ICCEA)
Last metadata update
المجتمع

Comments

تسجيل الدخول للانضمام إلى النقاش.

  1. لا توجد تعليقات بعد. ابدأ النقاش.