Residential Collegefalse
Status已發表Published
Adversarial example generation with adaptive gradient search for single and ensemble deep neural network
Xiao,Yatie; Pun,Chi Man; Liu,Bo
2020-08-01
Source PublicationInformation Sciences
ISSN0020-0255
Volume528Pages:147-167
Abstract

Deep Neural Networks (DNNs) have achieved remarkable success in specific domains, such as computer vision, audio processing, and natural language processing. However, researches indicate that deep neural networks are facing many security issues (e.g., adversarial attack, information forgery). In the field of image classification, adversarial samples generated by specific adversarial attack strategies can easily fool deep neural classification models into making unreliable predictions. We find that such adversarial attack algorithms induce large-scale pixel modifications in crafted images to maintain the effectiveness of the adversarial attack. Massive pixel modifications change the inherent characteristics of generated examples and cause large image distortion. To address the mentioned issues, we introduce an adaptive gradient-based adversarial attack method named Adaptive Iteration Fast Gradient Method (AI-FGM), which focuses on seeking the input's preceding gradient and adjusts the accumulation of perturbed entity adaptively for performing adversarial attacks. By maximizing the specific loss for generating adaptive gradient-based entities, AI-FGM calls for several gradient-based operators on the clean input to map crafted sample with the corresponding prediction directly. AI-FGM helps to reduce unnecessary gradient-based entity accumulation when processing adversary by adaptive gradient-based seeking strategy. Experimental results show that AI-FGM outperforms other gradient-based adversarial attackers in attacking deep neural classification models with fewer pixel modifications (AMP is 0.0017 with L norm in fooling Inception-v3) and higher success rate of invasion on deep neural classification networks in white-box and black-box attack strategy on public image datasets with different resolution.

KeywordDeep Neural Networks Adversarial Attack Adaptive Gradient Perturbation
DOI10.1016/j.ins.2020.04.022
URLView the original
Indexed BySCIE
Language英語English
WOS Research AreaComputer Science
WOS SubjectComputer Science, Information Systems
WOS IDWOS:000532827200009
Scopus ID2-s2.0-85083338932
Fulltext Access
Citation statistics
Document TypeJournal article
CollectionDEPARTMENT OF COMPUTER AND INFORMATION SCIENCE
Corresponding AuthorPun,Chi Man
AffiliationDepartment of Computer and Information Science,University of Macau,Macau,999078,Macao
First Author AffilicationUniversity of Macau
Corresponding Author AffilicationUniversity of Macau
Recommended Citation
GB/T 7714
Xiao,Yatie,Pun,Chi Man,Liu,Bo. Adversarial example generation with adaptive gradient search for single and ensemble deep neural network[J]. Information Sciences, 2020, 528, 147-167.
APA Xiao,Yatie., Pun,Chi Man., & Liu,Bo (2020). Adversarial example generation with adaptive gradient search for single and ensemble deep neural network. Information Sciences, 528, 147-167.
MLA Xiao,Yatie,et al."Adversarial example generation with adaptive gradient search for single and ensemble deep neural network".Information Sciences 528(2020):147-167.
Files in This Item:
There are no files associated with this item.
Related Services
Recommend this item
Bookmark
Usage statistics
Export to Endnote
Google Scholar
Similar articles in Google Scholar
[Xiao,Yatie]'s Articles
[Pun,Chi Man]'s Articles
[Liu,Bo]'s Articles
Baidu academic
Similar articles in Baidu academic
[Xiao,Yatie]'s Articles
[Pun,Chi Man]'s Articles
[Liu,Bo]'s Articles
Bing Scholar
Similar articles in Bing Scholar
[Xiao,Yatie]'s Articles
[Pun,Chi Man]'s Articles
[Liu,Bo]'s Articles
Terms of Use
No data!
Social Bookmark/Share
All comments (0)
No comment.
 

Items in the repository are protected by copyright, with all rights reserved, unless otherwise indicated.