Attacking convolutional neural network using differential evolution

被引:20
作者
Su J. [1 ]
Vargas D.V. [2 ]
Sakurai K. [2 ]
机构
[1] Graduate School of Information Science and Electrical Engineering, Kyushu University, Fukuoka
[2] Faculty of Information Science and Electrical Engineering, Kyushu University, Fukuoka
来源
IPSJ Transactions on Computer Vision and Applications | 2019年 / 11卷 / 01期
基金
日本科学技术振兴机构;
关键词
Adversarial machine learning; Artificial intelligence; Image processing;
D O I
10.1186/s41074-019-0053-3
中图分类号
学科分类号
摘要
The output of convolutional neural networks (CNNs) has been shown to be discontinuous which can make the CNN image classifier vulnerable to small well-tuned artificial perturbation. That is, images modified by conducting such alteration (i.e., adversarial perturbation) that make little difference to the human eyes can completely change the CNN classification results. In this paper, we propose a practical attack using differential evolution (DE) for generating effective adversarial perturbations. We comprehensively evaluate the effectiveness of different types of DEs for conducting the attack on different network structures. The proposed method only modifies five pixels (i.e., few-pixel attack), and it is a black-box attack which only requires the miracle feedback of the target CNN systems. The results show that under strict constraints which simultaneously control the number of pixels changed and overall perturbation strength, attacking can achieve 72.29%, 72.30%, and 61.28% non-targeted attack success rates, with 88.68%, 83.63%, and 73.07% confidence on average, on three common types of CNNs. The attack only requires modifying five pixels with 20.44, 14.28, and 22.98 pixel value distortion. Thus, we show that current deep neural networks are also vulnerable to such simpler black-box attacks even under very limited attack conditions. © 2019, The Author(s).
引用
收藏
相关论文
共 50 条
  • [41] Determining Rock Fragment Size Distribution Using a Convolutional Neural Network
    Sharifi, Elmira
    Farsangi, Mohamad Ali Ebrahimi
    Mansouri, Hamid
    Rashedi, Esmat
    RUDARSKO-GEOLOSKO-NAFTNI ZBORNIK, 2024, 39 (02): : 1 - 14
  • [42] Deep grading of mangoes using Convolutional Neural Network and Computer Vision
    Gururaj, Nirmala
    Vinod, Viji
    Vijayakumar, K.
    MULTIMEDIA TOOLS AND APPLICATIONS, 2023, 82 (25) : 39525 - 39550
  • [43] Contaminated Facade Identification Using Convolutional Neural Network and Image Processing
    Lee, Jiseok
    Hong, Jooyoung
    Park, Garam
    Kim, Hwa Soo
    Lee, Sungon
    Seo, TaeWon
    IEEE ACCESS, 2020, 8 (08) : 180010 - 180021
  • [44] Increasing of Convolutional Neural Network Performance Using Residue Number System
    Chervyakov, N. I.
    Lyakhov, P. A.
    Valueva, M. V.
    2017 INTERNATIONAL MULTI-CONFERENCE ON ENGINEERING, COMPUTER AND INFORMATION SCIENCES (SIBIRCON), 2017, : 135 - 140
  • [45] Efficient detection of refugees and migrants in Turkey using convolutional neural network
    Elebe, Talib Muhsen
    Kurnaz, Sefer
    PHYSICAL COMMUNICATION, 2023, 59
  • [46] Quick Roughness Evaluation of Cut Edges using a Convolutional Neural Network
    Stahl, J.
    Jauch, C.
    FOURTEENTH INTERNATIONAL CONFERENCE ON QUALITY CONTROL BY ARTIFICIAL VISION, 2019, 11172
  • [47] Micro Nucleus Detection in Human Lymphocytes Using Convolutional Neural Network
    Paliy, Ihor
    Lamonaca, Francesco
    Turchenko, Volodymyr
    Grimaldi, Domenico
    Sachenko, Anatoly
    ARTIFICIAL NEURAL NETWORKS-ICANN 2010, PT I, 2010, 6352 : 521 - +
  • [48] Potato late blight disease detection using convolutional neural network
    Islam M.Md.
    Islam A.
    Habib A.
    International Journal of Information and Communication Technology, 2023, 23 (04) : 346 - 370
  • [49] Crack Detection and Classification in Moroccan Pavement Using Convolutional Neural Network
    Hammouch, Wafae
    Chouiekh, Chaymae
    Khaissidi, Ghizlane
    Mrabti, Mostafa
    INFRASTRUCTURES, 2022, 7 (11)
  • [50] CT Cervical Spine Fracture Detection Using a Convolutional Neural Network
    Small, J. E.
    Osler, P.
    Paul, A. B.
    Kunst, M.
    AMERICAN JOURNAL OF NEURORADIOLOGY, 2021, 42 (07) : 1341 - 1347