paper-with-me

홈 › Papers

Adaptive Perturbation for Adversarial Attack

2021-11-27 · Zheng Yuan, Jie Zhang, Zhaoyan Jiang, Liangliang Li, Shiguang Shan

In recent years, the security of deep learning models achieves more and more attentions with the rapid development of neural networks, which are vulnerable to adversarial examples. Almost all existing gradient-based attack methods use the sign function in the generation to meet the requirement of perturbation budget on $L_\infty$ norm. However, we find that the sign function may be improper for generating adversarial examples since it modifies the exact gradient direction. Instead of using the sign function, we propose to directly utilize the exact gradient direction with a scaling factor for generating adversarial perturbations, which improves the attack success rates of adversarial examples even with fewer perturbations. At the same time, we also theoretically prove that this method can achieve better black-box transferability. Moreover, considering that the best scaling factor varies across different images, we propose an adaptive scaling factor generator to seek an appropriate scaling factor for each image, which avoids the computational cost for manually searching the scaling factor. Our method can be integrated with almost all existing gradient-based attack methods to further improve their attack success rates. Extensive experiments on the CIFAR10 and ImageNet datasets show that our method exhibits higher transferability and outperforms the state-of-the-art methods.

📄 PDF Abstract BibTeX arXiv:2111.13841

Code (0)

등록된 구현이 없습니다.

Tasks

Adversarial Attack

Similar Papers 제목 키워드 기반

Adaptive Generation of Unrestricted Adversarial Inputs

2019-05-07 · Isaac Dunn, Hadrien Pouget, Tom Melham, Daniel Kroening

Neural networks are vulnerable to adversarially-constructed perturbations of their inputs. Most research so far has considered perturbations of a fixed magnitude under some $l_p$ norm. Although studying these attacks is …

Consistent Valid Physically-Realizable Adversarial Attack against Crowd-flow Prediction Models

2023-03-05 · Hassan Ali, Muhammad Atif Butt, Fethi Filali, Ala Al-Fuqaha 외

Recent works have shown that deep learning (DL) models can effectively learn city-wide crowd-flow patterns, which can be used for more effective urban planning and smart city management. However, DL models have been know…

Adversarial AttackManagementvalid

Adaptive Smoothness-weighted Adversarial Training for Multiple Perturbations with Its Stability Analysis

2022-10-02 · Jiancong Xiao, Zeyu Qin, Yanbo Fan, Baoyuan Wu 외

Adversarial Training (AT) has been demonstrated as one of the most effective methods against adversarial examples. While most existing works focus on AT with a single type of perturbation e.g., the $\ell_\infty$ attacks)…

Adversarial Robustness

Benchmarking Adversarial Robustness of Image Shadow Removal with Shadow-adaptive Attacks

2024-03-15 · Chong Wang, Yi Yu, Lanqing Guo, Bihan Wen

Shadow removal is a task aimed at erasing regional shadows present in images and reinstating visually pleasing natural scenes with consistent illumination. While recent deep learning techniques have demonstrated impressi…

Adversarial AttackAdversarial RobustnessBenchmarkingImage Shadow Removal+1

Geometrically Adaptive Dictionary Attack on Face Recognition

2021-11-08 · Junyoung Byun, Hyojun Go, Changick Kim

CNN-based face recognition models have brought remarkable performance improvement, but they are vulnerable to adversarial perturbations. Recent studies have shown that adversaries can fool the models even if they can onl…

3D Face AlignmentFace AlignmentFace Recognition