Learning transferable targeted universal adversarial perturbations by sequential meta-learning

被引:0
|
作者
Weng, Juanjuan [1 ]
Luo, Zhiming [1 ]
Lin, Dazhen [1 ]
Li, Shaozi [1 ,2 ]
机构
[1] Xiamen Univ, Dept Artificial Intelligence, Xiamen 361005, Peoples R China
[2] Wuyi Univ, Fujian Key Lab Big Data Applicat & Intellectualiza, Wuyishan 354300, Peoples R China
关键词
Targeted adversarial attacks; Model-agnostic meta-learning; Data-free universal adversarial perturbations; Transfer-based black-box attacks;
D O I
10.1016/j.cose.2023.103584
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Recently, the transferability of adversarial perturbations in non-targeted scenarios has been extensively studied. However, changing the predictions of an unknown model to a pre-defined 'targeted' class still remains challenging. In this study, we aim to learn the targeted universal adversarial perturbations (UAPs) with higher transferability by the ensemble of multiple models. First, we observe the phenomenon that the logit of the target class will bias to a specific white-box model in existing ensemble-based attacks. To deal with the issue, we propose a normalized logit loss to narrow the margin of the targeted class's logits among different models. Besides, we introduce a novel sequential meta-learning optimization strategy to further increase transferability, consisting of the inner loop and the outer loop. In the inner loop, we sequentially learn task-specific targeted UAPs for each source model by jointly considering the perturbation from the previous model. In the outer loop, we optimize the task-agnostic targeted UAP by combining the targeted UAPs from the inner loop. Experimental results demonstrate the mutual benefits of the normalized logit loss and the sequential meta-learning optimization strategy for learning targeted adversarial perturbations, outperforming existing ensemble attacks in both white box and black-box settings. The source code of this study is available at: Link.
引用
收藏
页数:13
相关论文
共 50 条
  • [31] Meta-learning with backpropagation
    Younger, AS
    Hochreiter, S
    Conwell, PR
    IJCNN'01: INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS, VOLS 1-4, PROCEEDINGS, 2001, : 2001 - 2006
  • [32] TOOLS AND TASKS FOR LEARNING AND META-LEARNING
    Jaworski, Barbara
    JOURNAL OF MATHEMATICS TEACHER EDUCATION, 2005, 8 (05) : 359 - 361
  • [33] Tools and Tasks for Learning and Meta-learning
    Barbara Jaworski
    Journal of Mathematics Teacher Education, 2005, 8 (5) : 359 - 361
  • [34] Competitive Meta-Learning
    Boxi Weng
    Jian Sun
    Gao Huang
    Fang Deng
    Gang Wang
    Jie Chen
    IEEE/CAA Journal of Automatica Sinica, 2023, 10 (09) : 1902 - 1904
  • [35] On meta-learning rule learning heuristics
    Janssen, Frederik
    Fuernkranz, Johannes
    ICDM 2007: PROCEEDINGS OF THE SEVENTH IEEE INTERNATIONAL CONFERENCE ON DATA MINING, 2007, : 529 - 534
  • [36] Competitive Meta-Learning
    Weng, Boxi
    Sun, Jian
    Huang, Gao
    Deng, Fang
    Wang, Gang
    Chen, Jie
    IEEE-CAA JOURNAL OF AUTOMATICA SINICA, 2023, 10 (09) : 1902 - 1904
  • [37] Transferable Adversarial Defense by Fusing Reconstruction Learning and Denoising Learning
    Gao, Song
    Yao, Shaowen
    Li, Ruidong
    IEEE CONFERENCE ON COMPUTER COMMUNICATIONS WORKSHOPS (IEEE INFOCOM WKSHPS 2021), 2021,
  • [38] Hybrid-Task Meta-Learning: A GNN Approach for Scalable and Transferable Bandwidth Allocation
    Hao, Xin
    She, Changyang
    Yeoh, Phee Lep
    Liu, Yuhong
    Vucetic, Branka
    Li, Yonghui
    IEEE TRANSACTIONS ON WIRELESS COMMUNICATIONS, 2024, 23 (12) : 19820 - 19835
  • [39] Explainable and Transferable Loss Meta-Learning for Zero-Touch Anticipatory Network Management
    Collet, Alan
    Bazco-Nogueras, Antonio
    Banchs, Albert
    Fiore, Marco
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2024, 21 (03): : 2802 - 2823
  • [40] Learning Optimization-based Adversarial Perturbations for Attacking Sequential Recognition Models
    Xu, Xing
    Chen, Jiefu
    Xiao, Jinhui
    Wang, Zheng
    Yang, Yang
    Shen, Heng Tao
    MM '20: PROCEEDINGS OF THE 28TH ACM INTERNATIONAL CONFERENCE ON MULTIMEDIA, 2020, : 2802 - 2810