FineFool: A novel DNN object contour attack on image recognition based on the attention perturbation adversarial technique. Issue 104 (May 2021)
- Record Type:
- Journal Article
- Title:
- FineFool: A novel DNN object contour attack on image recognition based on the attention perturbation adversarial technique. Issue 104 (May 2021)
- Main Title:
- FineFool: A novel DNN object contour attack on image recognition based on the attention perturbation adversarial technique
- Authors:
- Chen, Jinyin
Zheng, Haibin
Xiong, Hui
Chen, Ruoxi
Du, Tianyu
Hong, Zhen
Ji, Shouling - Abstract:
- Highlights: Study the correlation between object contour and adversarial attack. FineFool concentrates perturbations near the object contour. Design attention perturbation adversarial technique for fewer perturbations. Graphical abstract: Figure: Graphic abstract of the FineFool attack method. The "benign example" is an image with a height H and width W and RGB channels. The "deep model" denotes the target DNN set to be attacked, which is trained on benign datasets. The "feature map" denotes the output of the DNN in a shallow feature layer, which has a height H' and width W' and a channel c, where H' and W' and c depend on the size of the convolution kernel. The "reconstructed feature map" is obtained by upsampling from the "feature map". The channel-spatial attention module is used to produce the channel-spatial attention weight Wc, which is multiplied in the channel of the feature map. Subsequently, the pixel-spatial attention module is used to produce the pixelspatial attention weights Wp, which are multiplied at each pixel point, resulting in an "attention map" with height H and width W and a channel one. Abstract: Deep neural networks (DNNs) have various applications owing to their feature learning ability. However, recent studies have shown that DNNs are vulnerable to adversarial examples. Currently, research on the generation of adversarial examples primarily focuses on improving the attack success rate (ASR) while reducing the perturbation size. By visualizing ofHighlights: Study the correlation between object contour and adversarial attack. FineFool concentrates perturbations near the object contour. Design attention perturbation adversarial technique for fewer perturbations. Graphical abstract: Figure: Graphic abstract of the FineFool attack method. The "benign example" is an image with a height H and width W and RGB channels. The "deep model" denotes the target DNN set to be attacked, which is trained on benign datasets. The "feature map" denotes the output of the DNN in a shallow feature layer, which has a height H' and width W' and a channel c, where H' and W' and c depend on the size of the convolution kernel. The "reconstructed feature map" is obtained by upsampling from the "feature map". The channel-spatial attention module is used to produce the channel-spatial attention weight Wc, which is multiplied in the channel of the feature map. Subsequently, the pixel-spatial attention module is used to produce the pixelspatial attention weights Wp, which are multiplied at each pixel point, resulting in an "attention map" with height H and width W and a channel one. Abstract: Deep neural networks (DNNs) have various applications owing to their feature learning ability. However, recent studies have shown that DNNs are vulnerable to adversarial examples. Currently, research on the generation of adversarial examples primarily focuses on improving the attack success rate (ASR) while reducing the perturbation size. By visualizing of heat maps, previous works have found that the feature extraction effect of DNNs is owing to the precise location of object contours and the provision of the correct attention to those areas. Therefore, the perturbations in adversarial examples will weaken the location of object contours in deep hidden layers and reduce the attention scope of the object area, which will lead to successful attacks. Inspired by this observation, we propose FineFool, a novel adversarial attack based on the attention perturbation adversarial technique, which includes channel-spatial attention and pixel-spatial attention . The former reduces the area of concern using DNNs while the latter achieves the error location of the object contours. By using the attention perturbation adversarial technique to target positions that are more vulnerable in legitimate examples, FineFool achieves a higher ASR with fewer perturbations compared with that of state-of-the-art adversarial attacks. Extensive experiments are carried out on MNIST, CIFAR10, and ImageNet datasets against six models. The results show that FineFool can achieve the best performance compared with the six baselines. More specifically, the mean ASR values of untargeted/targeted attack are 99.23% and 98.26% for FineFool on all datasets, respectively, which is the highest under white-box attack situations. The code of FineFool is open sourced at https://zenodo.org/record/4421611#.X . … (more)
- Is Part Of:
- Computers & security. Issue 104(2021)
- Journal:
- Computers & security
- Issue:
- Issue 104(2021)
- Issue Display:
- Volume 104, Issue 104 (2021)
- Year:
- 2021
- Volume:
- 104
- Issue:
- 104
- Issue Sort Value:
- 2021-0104-0104-0000
- Page Start:
- Page End:
- Publication Date:
- 2021-05
- Subjects:
- Adversarial attack -- Deep learning -- Attention perturbation adversarial technique -- Perturbation visualization -- Targeted attack
00-01 -- 99-00
Computer security -- Periodicals
Electronic data processing departments -- Security measures -- Periodicals
005.805 - Journal URLs:
- http://www.sciencedirect.com/science/journal/01674048 ↗
http://www.elsevier.com/journals ↗ - DOI:
- 10.1016/j.cose.2021.102220 ↗
- Languages:
- English
- ISSNs:
- 0167-4048
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 3394.781000
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 16144.xml