Learning transferable targeted universal adversarial perturbations by sequential meta-learning

被引:0
|
作者
Weng, Juanjuan [1 ]
Luo, Zhiming [1 ]
Lin, Dazhen [1 ]
Li, Shaozi [1 ,2 ]
机构
[1] Xiamen Univ, Dept Artificial Intelligence, Xiamen 361005, Peoples R China
[2] Wuyi Univ, Fujian Key Lab Big Data Applicat & Intellectualiza, Wuyishan 354300, Peoples R China
关键词
Targeted adversarial attacks; Model-agnostic meta-learning; Data-free universal adversarial perturbations; Transfer-based black-box attacks;
D O I
10.1016/j.cose.2023.103584
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Recently, the transferability of adversarial perturbations in non-targeted scenarios has been extensively studied. However, changing the predictions of an unknown model to a pre-defined 'targeted' class still remains challenging. In this study, we aim to learn the targeted universal adversarial perturbations (UAPs) with higher transferability by the ensemble of multiple models. First, we observe the phenomenon that the logit of the target class will bias to a specific white-box model in existing ensemble-based attacks. To deal with the issue, we propose a normalized logit loss to narrow the margin of the targeted class's logits among different models. Besides, we introduce a novel sequential meta-learning optimization strategy to further increase transferability, consisting of the inner loop and the outer loop. In the inner loop, we sequentially learn task-specific targeted UAPs for each source model by jointly considering the perturbation from the previous model. In the outer loop, we optimize the task-agnostic targeted UAP by combining the targeted UAPs from the inner loop. Experimental results demonstrate the mutual benefits of the normalized logit loss and the sequential meta-learning optimization strategy for learning targeted adversarial perturbations, outperforming existing ensemble attacks in both white box and black-box settings. The source code of this study is available at: Link.
引用
收藏
页数:13
相关论文
共 50 条
  • [1] Learning Transferable Adversarial Perturbations
    Nakka, Krishna Kanth
    Salzmann, Mathieu
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 34 (NEURIPS 2021), 2021, 34
  • [2] Meta-Learning Adversarial Bandit Algorithms
    Khodak, Mikhail
    Osadchiy, Ilya
    Harris, Keegan
    Balcan, Maria-Florina
    Levy, Kfir Y.
    Meir, Ron
    Wu, Zhiwei Steven
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 36 (NEURIPS 2023), 2023,
  • [3] Learning Universal Adversarial Perturbations with Generative Models
    Hayes, Jamie
    Danezis, George
    2018 IEEE SYMPOSIUM ON SECURITY AND PRIVACY WORKSHOPS (SPW 2018), 2018, : 43 - 49
  • [4] Towards Transferable Adversarial Examples Using Meta Learning
    Fan, Mingyuan
    Yin, Jia-Li
    Liu, Ximeng
    Guo, Wenzhong
    ALGORITHMS AND ARCHITECTURES FOR PARALLEL PROCESSING, ICA3PP 2021, PT I, 2022, 13155 : 178 - 192
  • [5] Adversarial Task Up-sampling for Meta-learning
    Wu, Yichen
    Huang, Long-Kai
    Wei, Ying
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 35 (NEURIPS 2022), 2022,
  • [6] Enhancing Fault Diagnosis in Industrial Processes through Adversarial Task Augmented Sequential Meta-Learning
    Sun, Dexin
    Fan, Yunsheng
    Wang, Guofeng
    APPLIED SCIENCES-BASEL, 2024, 14 (11):
  • [7] Transferable universal adversarial perturbations against speaker recognition systems
    Liu, Xiaochen
    Tan, Hao
    Zhang, Junjian
    Li, Aiping
    Gu, Zhaoquan
    WORLD WIDE WEB-INTERNET AND WEB INFORMATION SYSTEMS, 2024, 27 (03):
  • [8] PROPERTIES OF LEARNING MULTIPLICATIVE UNIVERSAL ADVERSARIAL PERTURBATIONS IN IMAGE DATA
    Zamichos, Alexandros
    Mygdalis, Vasileios
    Pitas, Ioannis
    2022 IEEE 32ND INTERNATIONAL WORKSHOP ON MACHINE LEARNING FOR SIGNAL PROCESSING (MLSP), 2022,
  • [9] META-LEARNING OF RBF NETWORKS IN SEQUENTIAL APPROXIMATE OPTIMIZATION
    Yun, Yeboon
    Yoon, Min
    JOURNAL OF NONLINEAR AND CONVEX ANALYSIS, 2021, 22 (12) : 2609 - 2622
  • [10] Substitute Meta-Learning for Black-Box Adversarial Attack
    Hu, Cong
    Xu, Hao-Qi
    Wu, Xiao-Jun
    IEEE SIGNAL PROCESSING LETTERS, 2022, 29 : 2472 - 2476