Defense Strategy of Adversarial Attack
At a glance
- Citations
- 0
- References
- 17
- Comments
- 0
Abstract
The adversarial attack technique is to cause slight interference to the deep learning model through adversarial samples so that the model’s prediction accuracy drops sharply. The FGSM method mainly utilizes the gradient descent method in the neural network, back-transmits the original data, and adds perturbations to obtain adversarial samples. Then such adversarial samples are generated for a specific model and a specific batch of data. This paper uses the generated adversarial examples to test LeNet and VGG11, VGG13, VGG16, and VGG19. For the rigor of the experiment, this paper uses the adversarial samples generated by VGG19 to test VGG11, VGG13, and VGG16. Through the above experiments, this paper obtains the aggressiveness of the same adversarial samples against different models and the commonality between the adversarial samples generated by different models so that we can get some valuable ideas in analyzing the characteristics of adversarial samples and defense strategies.
Publication details
- DOI
- 10.1109/iccsmt58129.2022.00091
- OpenAlex
- W4379929954
- Document type
- conference-paper
- Language
- EN
- Last metadata update
Comments
Log in to join the discussion.