A universal adversarial perturbations generation method based on feature aggregation
At a glance
- Citations
- 0
- References
- 27
- Comments
- 0
Abstract
Universal Adversarial Perturbations (UAP) is a sample-independent adversarial attack that can be added to all natural samples to change most of their predictive labels. Aiming at the problems of the existing universal adversarial attack methods in the field of automatic modulation recognition, such as the large amount of training samples needed, the complexity of the method training process, and the low success rate of the universal adversarial attack, this paper proposes a universal adversarial perturbation generation method based on feature aggregation. In this paper, we first introduce the generic adversarial attack layer selection method based on the neural collapse phenomenon, and then propose the feature clustering loss for generic adversarial perturbation generation, and introduce the training process of the algorithm. This paper conducts a large number of experiments on several datasets and models, and proposes multi-dimensional metrics to measure the performance of the generalized adversarial attack, which finally proves the effectiveness of the method in this paper.
Publication details
- DOI
- 10.1109/ricai64321.2024.10911623
- OpenAlex
- W4408401456
- Document type
- conference-paper
- Language
- EN
- Last metadata update
Comments
Log in to join the discussion.