Attacking convolutional neural network using differential evolution

被引:20
|
作者
Su J. [1 ]
Vargas D.V. [2 ]
Sakurai K. [2 ]
机构
[1] Graduate School of Information Science and Electrical Engineering, Kyushu University, Fukuoka
[2] Faculty of Information Science and Electrical Engineering, Kyushu University, Fukuoka
基金
日本科学技术振兴机构;
关键词
Adversarial machine learning; Artificial intelligence; Image processing;
D O I
10.1186/s41074-019-0053-3
中图分类号
学科分类号
摘要
The output of convolutional neural networks (CNNs) has been shown to be discontinuous which can make the CNN image classifier vulnerable to small well-tuned artificial perturbation. That is, images modified by conducting such alteration (i.e., adversarial perturbation) that make little difference to the human eyes can completely change the CNN classification results. In this paper, we propose a practical attack using differential evolution (DE) for generating effective adversarial perturbations. We comprehensively evaluate the effectiveness of different types of DEs for conducting the attack on different network structures. The proposed method only modifies five pixels (i.e., few-pixel attack), and it is a black-box attack which only requires the miracle feedback of the target CNN systems. The results show that under strict constraints which simultaneously control the number of pixels changed and overall perturbation strength, attacking can achieve 72.29%, 72.30%, and 61.28% non-targeted attack success rates, with 88.68%, 83.63%, and 73.07% confidence on average, on three common types of CNNs. The attack only requires modifying five pixels with 20.44, 14.28, and 22.98 pixel value distortion. Thus, we show that current deep neural networks are also vulnerable to such simpler black-box attacks even under very limited attack conditions. © 2019, The Author(s).
引用
收藏
相关论文
共 50 条
  • [21] A Liver Damage Prediction Using Partial Differential Segmentation with Improved Convolutional Neural Network
    Sumathy, B.
    Dadheech, Pankaj
    Jain, Monika
    Saxena, Ankur
    Hemalatha, S.
    Liu, Wenqi
    Nuagah, Stephen Jeswinde
    JOURNAL OF HEALTHCARE ENGINEERING, 2022, 2022
  • [22] Dynamic Differential Current-Based Transformer Protection Using Convolutional Neural Network
    Li Z.
    Jiao Z.
    He A.
    CSEE Journal of Power and Energy Systems, 2022,
  • [23] An Efficient Federated Convolutional Neural Network Scheme with Differential Privacy
    Zhang, Dayin
    Chen, Xiaojun
    Shi, Jinqiao
    EMERGING INFORMATION SECURITY AND APPLICATIONS, EISA 2022, 2022, 1641 : 173 - 190
  • [24] An approach for total organic carbon prediction using convolutional neural networks optimized by differential evolution
    Rodrigo Oliveira Silva
    Camila Martins Saporetti
    Zaher Mundher Yaseen
    Egberto Pereira
    Leonardo Goliatt
    Neural Computing and Applications, 2023, 35 : 20803 - 20817
  • [25] An approach for total organic carbon prediction using convolutional neural networks optimized by differential evolution
    Silva, Rodrigo Oliveira
    Saporetti, Camila Martins
    Yaseen, Zaher Mundher
    Pereira, Egberto
    Goliatt, Leonardo
    NEURAL COMPUTING & APPLICATIONS, 2023, 35 (28): : 20803 - 20817
  • [26] Gait Recognition Using Convolutional Neural Network
    Sheth, Abhishek
    Sharath, Meghana
    Reddy, Sai Charan
    Sindhu, K.
    INTERNATIONAL JOURNAL OF ONLINE AND BIOMEDICAL ENGINEERING, 2023, 19 (01) : 107 - 118
  • [27] OCT SEGMENTATION USING CONVOLUTIONAL NEURAL NETWORK
    George, Neetha
    Jiji, C., V
    2020 IEEE 17TH INTERNATIONAL SYMPOSIUM ON BIOMEDICAL IMAGING WORKSHOPS (IEEE ISBI WORKSHOPS 2020), 2020,
  • [28] Schizophrenia Detection Using Convolutional Neural Network
    Skunda, Juraj
    Polec, Jaroslav
    Nerusil, Boris
    Malisova, Eva
    PROCEEDINGS OF 63RD INTERNATIONAL SYMPOSIUM ELMAR-2021, 2021, : 151 - 154
  • [29] Vehicle Tracking using Convolutional Neural Network
    Shruthi, S.
    WORLD CONGRESS ON ENGINEERING, WCE 2011, VOL II, 2011, : 1052 - 1055
  • [30] Image Synthesis using Convolutional Neural Network
    Bhat, Ganesh
    Dharwadkar, Shrikant
    Reddy, N. V. Subba
    Shivaprasad, G.
    2017 2ND IEEE INTERNATIONAL CONFERENCE ON RECENT TRENDS IN ELECTRONICS, INFORMATION & COMMUNICATION TECHNOLOGY (RTEICT), 2017, : 689 - 691