conference-paper

ANIS: attention and noise fusion to improve adversarial attack

Research footprint

At a glance

Citations
0
References
29
Comments
0
Paper overview

Abstract

In recent years, adversarial attacks have attracted more and more concentration, and various attack methods have made them a significant threat to deep neural network (DNN) security. However, most of the current research focuses on the attack algorithm without paying awareness to the critical information of the image itself. This paper proposes ANIS, a flexible, attention-guided noise injection system. The system combines image processing techniques with adversarial examples to inject different types of noise into areas of varying importance. It is an architecture that integrates easily with other attack algorithms. After testing, we confirmed that ANIS could improve the success rate of attacks, making it more difficult for defense systems to defend. We also compared the performance of different adversarial attack algorithms combined with ANIS and found FGSM with the most noticeable improvement in attack effect.

Record transparency

Publication details

DOI
10.1117/12.3035110
OpenAlex
W4400828220
Document type
conference-paper
Language
EN
Last metadata update
Community

Comments

Log in to join the discussion.

  1. No comments yet. Start the discussion.