conference-paper

A Fast White-Box Adversarial Attack using Shadows for Convolutional Neural Networks

Research footprint

At a glance

الاستشهادات
0
المراجع
16
Comments
0
Paper overview

Abstract

In resource-constrained contexts, rapid and efficient model testing is crucial. This paper proposes a Fast White-box Shadow Attack named FWSA for convolutional neural networks. The proposed method aims to generate adversarial examples with low computational cost. From an input image, the main idea is to add shadow perturbation to specific location of the input image. The shadow perturbation is quickly generated by using the gradient of the target model with respect to the clean image. These adversarial examples can be used to enhance the robustness of the target model. To demonstrate the effectiveness of FWSA, the experiment is conducted on two common datasets including LISA and GTSRB. In term of attack performance, FWSA generates adversarial examples approximately 19.17 to 68.63 times faster than BSA, while maintaining an approximate average SSIM. Additionally, FWSA improves target model robustness by up to 24.42% compared to BSA. These results show the effectiveness of the proposed method in practice.

Record transparency

Publication details

DOI
10.1109/kse63888.2024.11063568
OpenAlex
W4412346838
Document type
conference-paper
Language
EN
Last metadata update
المجتمع

Comments

تسجيل الدخول للانضمام إلى النقاش.

  1. لا توجد تعليقات بعد. ابدأ النقاش.