Adaptive iterative attack towards explainable adversarial robustness. (September 2020)
- Record Type:
- Journal Article
- Title:
- Adaptive iterative attack towards explainable adversarial robustness. (September 2020)
- Main Title:
- Adaptive iterative attack towards explainable adversarial robustness
- Authors:
- Shi, Yucheng
Han, Yahong
Zhang, Quanxin
Kuang, Xiaohui - Abstract:
- Highlights: We demonstrate the relationship between step size and iterative attack effect. We design the first iterative attack adaptively allocates step size. We achieve high attack effect with various models with two different norms. We visualize attack trajectories to show the motivation of adjustment on stepsize. Abstract: Image classifiers based on deep neural networks show severe vulnerability when facing adversarial examples crafted on purpose. Designing more effective and efficient adversarial attacks is attracting considerable interest due to its potential contribution to interpretability of deep learning and validation of neural networks' robustness. However, current iterative attacks use a fixed step size for each noise-adding step, making further investigation into the effect of variable step size on model robustness ripe for exploration. We prove that if the upper bound of noise added to the original image is fixed, the attack effect can be improved if the step size is positively correlated with the gradient obtained at each step by querying the target model. In this paper, we propose Ada-FGSM (Adaptive FGSM), a new iterative attack that adaptively allocates step size of noises according to gradient information at each step. Improvement of success rate and accuracy decrease measured on ImageNet with multiple models emphasizes the validity of our method. We analyze the process of iterative attack by visualizing their trajectory and gradient contour, and furtherHighlights: We demonstrate the relationship between step size and iterative attack effect. We design the first iterative attack adaptively allocates step size. We achieve high attack effect with various models with two different norms. We visualize attack trajectories to show the motivation of adjustment on stepsize. Abstract: Image classifiers based on deep neural networks show severe vulnerability when facing adversarial examples crafted on purpose. Designing more effective and efficient adversarial attacks is attracting considerable interest due to its potential contribution to interpretability of deep learning and validation of neural networks' robustness. However, current iterative attacks use a fixed step size for each noise-adding step, making further investigation into the effect of variable step size on model robustness ripe for exploration. We prove that if the upper bound of noise added to the original image is fixed, the attack effect can be improved if the step size is positively correlated with the gradient obtained at each step by querying the target model. In this paper, we propose Ada-FGSM (Adaptive FGSM), a new iterative attack that adaptively allocates step size of noises according to gradient information at each step. Improvement of success rate and accuracy decrease measured on ImageNet with multiple models emphasizes the validity of our method. We analyze the process of iterative attack by visualizing their trajectory and gradient contour, and further explain the vulnerability of deep neural networks to variable step size adversarial examples. … (more)
- Is Part Of:
- Pattern recognition. Volume 105(2020:Sep.)
- Journal:
- Pattern recognition
- Issue:
- Volume 105(2020:Sep.)
- Issue Display:
- Volume 105 (2020)
- Year:
- 2020
- Volume:
- 105
- Issue Sort Value:
- 2020-0105-0000-0000
- Page Start:
- Page End:
- Publication Date:
- 2020-09
- Subjects:
- Adversarial example -- Adversarial attack -- Image classification
Pattern perception -- Periodicals
Perception des structures -- Périodiques
Patroonherkenning
006.4 - Journal URLs:
- http://www.sciencedirect.com/science/journal/00313203 ↗
http://www.sciencedirect.com/ ↗ - DOI:
- 10.1016/j.patcog.2020.107309 ↗
- Languages:
- English
- ISSNs:
- 0031-3203
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 13473.xml