An Adversarial Network-based Multi-model Black-box Attack

被引:0
|
作者
Lin, Bin [1 ]
Chen, Jixin [2 ]
Zhang, Zhihong [3 ]
Lai, Yanlin [2 ]
Wu, Xinlong [2 ]
Tian, Lulu [4 ]
Cheng, Wangchi [5 ]
机构
[1] Sichuan Normal Univ, Chengdu 610066, Peoples R China
[2] Southwest Petr Univ, Sch Comp Sci, Chengdu 610500, Peoples R China
[3] AECC Sichuan Gas Turbine Estab, Mianyang 621700, Sichuan, Peoples R China
[4] Brunel Univ London, Uxbridge UB8 3PH, Middx, England
[5] Inst Logist Sci & Technol, Beijing 100166, Peoples R China
关键词
Black-box attack; adversarial examples; GAN; multi-model; deep neural networks;
D O I
10.32604/iasc.2021.016818
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Researches have shown that Deep neural networks (DNNs) are vulnerable to adversarial examples. In this paper, we propose a generative model to explore how to produce adversarial examples that can deceive multiple deep learning models simultaneously. Unlike most of popular adversarial attack algorithms, the one proposed in this paper is based on the Generative Adversarial Networks (GAN). It can quickly produce adversarial examples and perform black-box attacks on multi-model. To enhance the transferability of the samples generated by our approach, we use multiple neural networks in the training process. Experimental results on MNIST showed that our method can efficiently generate adversarial examples. Moreover, it can successfully attack various classes of deep neural networks at the same time, such as fully connected neural networks (FCNN), convolutional neural networks (CNN) and recurrent neural networks (RNN). We performed a black-box attack on VGG16 and the experimental results showed that when the test data classes are ten (0-9), the attack success rate is 97.68%, and when the test data classes are seven (0-6), the attack success rate is up to 98.25%.
引用
收藏
页码:641 / 649
页数:9
相关论文
共 50 条
  • [21] An efficient general black-box adversarial attack approach based on multi-objective optimization for high dimensional images
    Zhang, Chunkai
    Guo, Xin
    Deng, Yepeng
    Wang, Xuan
    Han, Peiyi
    Liu, Chuanyi
    Zhang, Hanyu
    COMPUTERS & ELECTRICAL ENGINEERING, 2021, 95
  • [22] HYBRID ADVERSARIAL SAMPLE CRAFTING FOR BLACK-BOX EVASION ATTACK
    Zheng, Juan
    He, Zhimin
    Lin, Zhe
    2017 INTERNATIONAL CONFERENCE ON WAVELET ANALYSIS AND PATTERN RECOGNITION (ICWAPR), 2017, : 236 - 242
  • [23] Black-box Adversarial Attack on License Plate Recognition System
    Chen J.-Y.
    Shen S.-J.
    Su M.-M.
    Zheng H.-B.
    Xiong H.
    Zidonghua Xuebao/Acta Automatica Sinica, 2021, 47 (01): : 121 - 135
  • [24] Evolutionary Multilabel Adversarial Examples: An Effective Black-Box Attack
    Kong L.
    Luo W.
    Zhang H.
    Liu Y.
    Shi Y.
    IEEE Transactions on Artificial Intelligence, 2023, 4 (03): : 562 - 572
  • [25] An Evolutionary-Based Black-Box Attack to Deep Neural Network Classifiers
    Yutian Zhou
    Yu-an Tan
    Quanxin Zhang
    Xiaohui Kuang
    Yahong Han
    Jingjing Hu
    Mobile Networks and Applications, 2021, 26 : 1616 - 1629
  • [26] An Evolutionary-Based Black-Box Attack to Deep Neural Network Classifiers
    Zhou, Yutian
    Tan, Yu-an
    Zhang, Quanxin
    Kuang, Xiaohui
    Han, Yahong
    Hu, Jingjing
    MOBILE NETWORKS & APPLICATIONS, 2021, 26 (04) : 1616 - 1629
  • [27] GenDroid: A query-efficient black-box android adversarial attack framework
    Xu, Guangquan
    Shao, Hongfei
    Cui, Jingyi
    Bai, Hongpeng
    Li, Jiliang
    Bai, Guangdong
    Liu, Shaoying
    Meng, Weizhi
    Zheng, Xi
    COMPUTERS & SECURITY, 2023, 132
  • [28] Boosting Black-Box Adversarial Attacks with Meta Learning
    Fu, Junjie
    Sun, Jian
    Wang, Gang
    2022 41ST CHINESE CONTROL CONFERENCE (CCC), 2022, : 7308 - 7313
  • [29] A CMA-ES-Based Adversarial Attack Against Black-Box Object Detectors
    Lyu Haoran
    Tan Yu'an
    Xue Yuan
    Wang Yajie
    Xue Jingfeng
    CHINESE JOURNAL OF ELECTRONICS, 2021, 30 (03) : 406 - 412
  • [30] SSQLi: A Black-Box Adversarial Attack Method for SQL Injection Based on Reinforcement Learning
    Guan, Yuting
    He, Junjiang
    Li, Tao
    Zhao, Hui
    Ma, Baoqiang
    FUTURE INTERNET, 2023, 15 (04):