EnsembleFool: A method to generate adversarial examples based on model fusion strategy. Issue 107 (August 2021)
- Record Type:
- Journal Article
- Title:
- EnsembleFool: A method to generate adversarial examples based on model fusion strategy. Issue 107 (August 2021)
- Main Title:
- EnsembleFool: A method to generate adversarial examples based on model fusion strategy
- Authors:
- Peng, Wenyu
Liu, Renyang
Wang, Ruxin
Cheng, Taining
Wu, Zifeng
Cai, Li
Zhou, Wei - Abstract:
- Abstract: Deep neural networks have been shown vulnerable to adversarial attacks launched by adversarial examples. These examples' transferability makes an attack in the real-world feasible, which poses a security threat to deep learning. Considering the limited representation capacity of a single deep model, the transferability of an adversarial example generated by a single attack model would cause the failure of attacking other different models. In this paper, we propose a new adversarial attack method, named EnsembleFool, which flexibly integrates multiple models to enhance adversarial examples' transferability. Specifically, the model confidence concerning an input example reveals the risk of a successful attack. In an iterative attacking case, the result of a previous attack could guide us to enforce a new attack that possesses a higher probability of success. Regarding this, we design a series of integration strategies to improve the adversarial examples in each iteration. Extensive experiments on ImageNet indicate that the proposed method has superior attack performance and transferability than state-of-the-art methods.
- Is Part Of:
- Computers & security. Issue 107(2021)
- Journal:
- Computers & security
- Issue:
- Issue 107(2021)
- Issue Display:
- Volume 107, Issue 107 (2021)
- Year:
- 2021
- Volume:
- 107
- Issue:
- 107
- Issue Sort Value:
- 2021-0107-0107-0000
- Page Start:
- Page End:
- Publication Date:
- 2021-08
- Subjects:
- Deep learning -- Adversarial examples -- Ensemble models -- Self-adaptive -- White-box attack -- Transferability
Computer security -- Periodicals
Electronic data processing departments -- Security measures -- Periodicals
005.805 - Journal URLs:
- http://www.sciencedirect.com/science/journal/01674048 ↗
http://www.elsevier.com/journals ↗ - DOI:
- 10.1016/j.cose.2021.102317 ↗
- Languages:
- English
- ISSNs:
- 0167-4048
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 3394.781000
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 17259.xml