TransNoise: Transferable Universal Adversarial Noise for Adversarial Attack

被引:0
|
作者
Wei, Yier [1 ]
Gao, Haichang [1 ]
Wang, Yufei [1 ]
Liu, Huan [1 ]
Gao, Yipeng [1 ]
Luo, Sainan [1 ]
Guo, Qianwen [2 ]
机构
[1] Xidian Univ, Sch Comp Sci & Technol, Xian 710071, Peoples R China
[2] SongShan Lab, Zhengzhou 452470, Peoples R China
关键词
Adversarial attack; Universal adversarial noise; Deep neural networks;
D O I
10.1007/978-3-031-44192-9_16
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Deep neural networks have been proven to be vulnerable to adversarial attacks. The early attacks mostly involved image-specific approaches that generated specific adversarial noises for each individual image. More recent studies have further demonstrated that neural networks can also be fooled by image-agnostic noises, called "universal adversarial perturbation". However, the current universal adversarial attacks mainly focus on untargeted attacks and exhibit poor transferability. In this paper, we propose TransNoise, a new approach for implementing a transferable universal adversarial attack that involves modifying only a few pixels of the image. Our approach achieves state-of-art success rates in the universal adversarial attack domain for both targeted and nontarget settings. The experimental results demonstrate that our method outperforms the current methods from three aspects of universality: 1) by adding our universal adversarial noises to different images, the fooling rates of our method on the target model are almost all above 95%; 2) when no training data are available for the targeted model, our method is still able to implement targeted attacks; 3) the method transfers well across different models in the untargeted setting.
引用
收藏
页码:193 / 205
页数:13
相关论文
共 50 条
  • [31] Transferable Adversarial Perturbations
    Zhou, Wen
    Hou, Xin
    Chen, Yongjun
    Tang, Mengyun
    Huang, Xiangqi
    Gan, Xiang
    Yang, Yong
    COMPUTER VISION - ECCV 2018, PT XIV, 2018, 11218 : 471 - 486
  • [32] Adversarial Mask: Real-World Universal Adversarial Attack on Face Recognition Models
    Zolfi, Alon
    Avidan, Shai
    Elovici, Yuval
    Shabtai, Asaf
    MACHINE LEARNING AND KNOWLEDGE DISCOVERY IN DATABASES, ECML PKDD 2022, PT III, 2023, 13715 : 304 - 320
  • [33] Training NLI Models Through Universal Adversarial Attack
    Lin, Jieyu
    Liu, Wei
    Zou, Jiajie
    Ding, Nai
    CHINESE COMPUTATIONAL LINGUISTICS, CCL 2023, 2023, 14232 : 306 - 324
  • [34] Speckle-Variant Attack: Toward Transferable Adversarial Attack to SAR Target Recognition
    Peng, Bowen
    Peng, Bo
    Zhou, Jie
    Xia, Jingyuan
    Liu, Li
    IEEE GEOSCIENCE AND REMOTE SENSING LETTERS, 2022, 19
  • [35] UNIVERSAL ADVERSARIAL ATTACK AGAINST SPEAKER RECOGNITION MODELS
    Hanina, Shoham
    Zolfi, Alon
    Elovici, Yuval
    Shabtai, Asaf
    2024 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH AND SIGNAL PROCESSING, ICASSP 2024, 2024, : 4860 - 4864
  • [36] Adv-Attribute: Inconspicuous and Transferable Adversarial Attack on Face Recognition
    Jia, Shuai
    Yin, Bangjie
    Yao, Taiping
    Ding, Shouhong
    Shen, Chunhua
    Yang, Xiaokang
    Ma, Chao
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 35 (NEURIPS 2022), 2022,
  • [37] On the Robustness of Deep Learning Models to Universal Adversarial Attack
    Karim, Rezaul
    Islam, Md Amirul
    Mohammed, Noman
    Bruce, Neil D. B.
    2018 15TH CONFERENCE ON COMPUTER AND ROBOT VISION (CRV), 2018, : 55 - 62
  • [38] Cocktail Universal Adversarial Attack on Deep Neural Networks
    Li, Shaoxin
    Li, Xiaofeng
    Che, Xin
    Li, Xintong
    Zhang, Yong
    Chu, Lingyang
    COMPUTER VISION - ECCV 2024, PT LXV, 2025, 15123 : 396 - 412
  • [39] Universal Sparse Adversarial Attack on Video Recognition Models
    Li, Haoxuan
    Wang, Zheng
    INTERNATIONAL JOURNAL OF MULTIMEDIA DATA ENGINEERING & MANAGEMENT, 2021, 12 (03):
  • [40] Universal Adversarial Attack on Attention and the Resulting Dataset DAmageNet
    Chen, Sizhe
    He, Zhengbao
    Sun, Chengjin
    Yang, Jie
    Huang, Xiaolin
    IEEE TRANSACTIONS ON PATTERN ANALYSIS AND MACHINE INTELLIGENCE, 2022, 44 (04) : 2188 - 2197