Low-epsilon adversarial attack against a neural network online image stream classifier

被引:8
|
作者
Arjomandi, Hossein Mohasel [1 ]
Khalooei, Mohammad [1 ]
Amirmazlaghani, Maryam [1 ]
机构
[1] Amirkabir Univ Technol, Comp Engn Dept, Tehran, Iran
关键词
Adversarial attack; Image classification; Image stream; Optimization; Regularization;
D O I
10.1016/j.asoc.2023.110760
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
An adversary intercepts a stream of images between a sender and a receiver neural network classifier. To minimize its footprint, the adversary only attacks a limited number of images within the stream. The adversary is interested in maximizing the number of successfully conducted attacks among all performed attacks. Upon the arrival of each image and before the arrival of the following image, the adversary must irrevocably decide whether it wants to attack the current image or not. The target model is a fixed deep neural network that may use any form of regularization. The adversary has query access to the target model, which can feed images and obtain the loss, which may contain regularization and classification loss terms. Since this paper's proposed method needs classification loss term alone, it also suggests a novel method in which the adversary estimates the regularization loss term and eliminates it. All images are partitioned into three groups based on their after-attack classification loss and treated according to their group. Moreover, this paper provides some promising test results on various datasets. (c) 2023 Elsevier B.V. All rights reserved.
引用
收藏
页数:13
相关论文
共 50 条
  • [21] Online Robust Lagrangian Support Vector Machine against Adversarial Attack
    Ma, Yue
    He, Yiwei
    Tian, Yingjie
    6TH INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY AND QUANTITATIVE MANAGEMENT, 2018, 139 : 173 - 181
  • [22] Adversarial Attack Defense Based on the Deep Image Prior Network
    Sutanto, Richard Evan
    Lee, Sukho
    INFORMATION SCIENCE AND APPLICATIONS, 2020, 621 : 519 - 526
  • [23] A DoS attack detection method based on adversarial neural network
    Li, Yang
    Wu, Haiyan
    PEERJ COMPUTER SCIENCE, 2024, 10
  • [24] Parametric Noise Injection: Trainable Randomness to Improve Deep Neural Network Robustness against Adversarial Attack
    He, Zhezhi
    Rakin, Adnan Siraj
    Fan, Deliang
    2019 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR 2019), 2019, : 588 - 597
  • [25] PANDA: Practical Adversarial Attack Against Network Intrusion Detection
    Swain, Subrat Kumar
    Kumar, Vireshwar
    Bai, Guangdong
    Kim, Dan Dongseong
    2024 54TH ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS-SUPPLEMENTAL VOLUME, DSN-S 2024, 2024, : 28 - 32
  • [26] POLSAR IMAGE CLASSIFICATION VIA AUXILIARY CLASSIFIER GENERATIVE ADVERSARIAL NETWORK
    Xie, Wen
    Yang, Xin
    Wang, Ruonan
    Zhao, Feng
    2022 IEEE INTERNATIONAL GEOSCIENCE AND REMOTE SENSING SYMPOSIUM (IGARSS 2022), 2022, : 1205 - 1208
  • [27] GanDef: A GAN Based Adversarial Training Defense for Neural Network Classifier
    Liu, Guanxiong
    Khalil, Issa
    Khreishah, Abdallah
    ICT SYSTEMS SECURITY AND PRIVACY PROTECTION, SEC 2019, 2019, 562 : 19 - 32
  • [28] A Network Security Classifier Defense: Against Adversarial Machine Learning Attacks
    De Lucia, Michael J.
    Cotton, Chase
    PROCEEDINGS OF THE 2ND ACM WORKSHOP ON WIRELESS SECURITY AND MACHINE LEARNING, WISEML 2020, 2020, : 67 - 73
  • [29] Toward Robust Neural Image Compression: Adversarial Attack and Model Finetuning
    Chen, Tong
    Ma, Zhan
    IEEE TRANSACTIONS ON CIRCUITS AND SYSTEMS FOR VIDEO TECHNOLOGY, 2023, 33 (12) : 7842 - 7856
  • [30] A shape classifier by using image projection and a neural network
    Hou, TH
    Pern, MD
    INTERNATIONAL JOURNAL OF PATTERN RECOGNITION AND ARTIFICIAL INTELLIGENCE, 2000, 14 (02) : 225 - 242