ADAPTIVE WARPING NETWORK FOR TRANSFERABLE ADVERSARIAL ATTACKS

被引:1
|
作者
Son, Minji [1 ]
Kwon, Myung-Joon [1 ]
Kim, Hee-Seon [1 ]
Byun, Junyoung [1 ]
Cho, Seungju [1 ]
Kim, Changick [1 ]
机构
[1] Korea Adv Inst Sci & Technol KAIST, Sch Elect Engn, Daejeon, South Korea
关键词
Adversarial Attacks; Transfer-based Attacks; Transferability; Input Transformation; Warping;
D O I
10.1109/ICIP46576.2022.9897701
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Deep Neural Networks (DNNs) are extremely susceptible to adversarial examples, which are crafted by intentionally adding imperceptible perturbations to clean images. Due to potential threats of adversarial attacks in practice, black-box transfer-based attacks are carefully studied to identify the vulnerability of DNNs. Unfortunately, transfer-based attacks often fail to achieve high transferability because the adversarial examples tend to overfit the source model. Applying input transformation is one of the most effective methods to avoid such overfitting. However, most previous input transformation methods obtain limited transferability because these methods utilize fixed transformations for all images. To solve the problem, we propose an Adaptive Warping Network (AWN), which searches for appropriate warping to the individual data. Specifically, AWN optimizes the warping, which mitigates the effect of adversarial perturbations in each iteration. The adversarial examples are generated to become robust against such strong transformations. Extensive experimental results on the ImageNet dataset demonstrate that AWN outperforms the existing input transformation methods in terms of transferability.
引用
收藏
页码:3056 / 3060
页数:5
相关论文
共 50 条
  • [41] Adaptive Normalized Attacks for Learning Adversarial Attacks and Defenses in Power Systems
    Tian, Jiwei
    Li, Tengyao
    Shang, Fute
    Cao, Kunrui
    Li, Jing
    Ozay, Mete
    2019 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, CONTROL, AND COMPUTING TECHNOLOGIES FOR SMART GRIDS (SMARTGRIDCOMM), 2019,
  • [42] A Transferable Adaptive Domain Adversarial Neural Network for Virtual Reality Augmented EMG-Based Gesture Recognition
    Cote-Allard, Ulysse
    Gagnon-Turcotte, Gabriel
    Phinyomark, Angkoon
    Glette, Kyrre
    Scheme, Erik
    Laviolette, Francois
    Gosselin, Benoit
    IEEE TRANSACTIONS ON NEURAL SYSTEMS AND REHABILITATION ENGINEERING, 2021, 29 : 546 - 555
  • [43] Rethinking multi-spatial information for transferable adversarial attacks on speaker recognition systems
    Zhang, Junjian
    Tan, Hao
    Wang, Le
    Qian, Yaguan
    Gu, Zhaoquan
    CAAI TRANSACTIONS ON INTELLIGENCE TECHNOLOGY, 2024, 9 (03) : 620 - 631
  • [44] FACL-Attack: Frequency-Aware Contrastive Learning for Transferable Adversarial Attacks
    Yang, Hunmin
    Jeong, Jongoh
    Yoon, Kuk-Jin
    THIRTY-EIGHTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, VOL 38 NO 6, 2024, : 6494 - 6502
  • [45] Transferable Adversarial Perturbations
    Zhou, Wen
    Hou, Xin
    Chen, Yongjun
    Tang, Mengyun
    Huang, Xiangqi
    Gan, Xiang
    Yang, Yong
    COMPUTER VISION - ECCV 2018, PT XIV, 2018, 11218 : 471 - 486
  • [46] GCMA: Generative Cross-Modal Transferable Adversarial Attacks from Images to Videos
    Chen, Kai
    Wei, Zhipeng
    Chen, Jingjing
    Wu, Zuxuan
    Jiang, Yu-Gang
    PROCEEDINGS OF THE 31ST ACM INTERNATIONAL CONFERENCE ON MULTIMEDIA, MM 2023, 2023, : 698 - 708
  • [47] Reconstructing images with attention generative adversarial network against adversarial attacks
    Shen, Xiong
    Lu, Yiqin
    Cheng, Zhe
    Mao, Zhongshu
    Yang, Zhang
    Qin, Jiancheng
    JOURNAL OF ELECTRONIC IMAGING, 2024, 33 (03) : 33029
  • [48] Adaptive Image Reconstruction for Defense Against Adversarial Attacks
    Yang, Yanan
    Shih, Frank Y.
    Chang, I-Cheng
    INTERNATIONAL JOURNAL OF PATTERN RECOGNITION AND ARTIFICIAL INTELLIGENCE, 2022, 36 (12)
  • [49] On the Detection of Adaptive Adversarial Attacks in Speaker Verification Systems
    Chen, Zesheng
    IEEE INTERNET OF THINGS JOURNAL, 2023, 10 (18) : 16271 - 16283
  • [50] An adaptive randomized and secured approach against adversarial attacks
    Dhamija, Lovi
    Garg, Urvashi
    INFORMATION SECURITY JOURNAL, 2023, 32 (06): : 401 - 416