Boosting adversarial attacks with transformed gradient. Issue 118 (July 2022)
- Record Type:
- Journal Article
- Title:
- Boosting adversarial attacks with transformed gradient. Issue 118 (July 2022)
- Main Title:
- Boosting adversarial attacks with transformed gradient
- Authors:
- He, Zhengyun
Duan, Yexin
Zhang, Wu
Zou, Junhua
He, Zhengfang
Wang, Yunyun
Pan, Zhisong - Abstract:
- Abstract: Deep neural networks (DNNs) are vulnerable to adversarial examples, which are crafted by adding imperceptible perturbations to benign examples. Increasing the attack success rate usually requires a larger noise magnitude, which leads to noticeable noise. To this end, we propose a Transformed Gradient method (TG), which achieves a higher attack success rate with lower perturbations against the target model, i.e. an ensemble of black-box defense models. It consists of three steps: original gradient accumulation, gradient amplification, and gradient truncation. Besides, we introduce the Fr e ´ chet Inception Distance (FID) and Learned Perceptual Image Patch Similarity (LPIPS) respectively to evaluate fidelity and perceived distance from the original example, which is more comprehensive than only using L ∞ norm as evaluation metrics. Furthermore, we propose optimizing coefficients of the source-model ensemble to improve adversarial attacks. Extensive experimental results demonstrate that the perturbations of adversarial examples generated by our proposed method are less than the state-of-the-art baselines, namely MI, DI, TI, RF-DE based on vanilla iterative FGSM and their combinations. Compared with the baseline method, the average black-box attack success rate and total score are improved by 6.6% and 13.8, respectively. We make our codes public at Github https://github.com/Hezhengyun/Transformed-Gradient .
- Is Part Of:
- Computers & security. Issue 118(2022)
- Journal:
- Computers & security
- Issue:
- Issue 118(2022)
- Issue Display:
- Volume 118, Issue 118 (2022)
- Year:
- 2022
- Volume:
- 118
- Issue:
- 118
- Issue Sort Value:
- 2022-0118-0118-0000
- Page Start:
- Page End:
- Publication Date:
- 2022-07
- Subjects:
- Deep neural networks -- Image classification -- Adversarial examples -- Adversarial machine learning -- Adversarial attack -- Transferability
Computer security -- Periodicals
Electronic data processing departments -- Security measures -- Periodicals
005.805 - Journal URLs:
- http://www.sciencedirect.com/science/journal/01674048 ↗
http://www.elsevier.com/journals ↗ - DOI:
- 10.1016/j.cose.2022.102720 ↗
- Languages:
- English
- ISSNs:
- 0167-4048
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 3394.781000
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 22246.xml