An Adversarial Network-based Multi-model Black-box Attack

被引:0
|
作者
Lin, Bin [1 ]
Chen, Jixin [2 ]
Zhang, Zhihong [3 ]
Lai, Yanlin [2 ]
Wu, Xinlong [2 ]
Tian, Lulu [4 ]
Cheng, Wangchi [5 ]
机构
[1] Sichuan Normal Univ, Chengdu 610066, Peoples R China
[2] Southwest Petr Univ, Sch Comp Sci, Chengdu 610500, Peoples R China
[3] AECC Sichuan Gas Turbine Estab, Mianyang 621700, Sichuan, Peoples R China
[4] Brunel Univ London, Uxbridge UB8 3PH, Middx, England
[5] Inst Logist Sci & Technol, Beijing 100166, Peoples R China
关键词
Black-box attack; adversarial examples; GAN; multi-model; deep neural networks;
D O I
10.32604/iasc.2021.016818
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Researches have shown that Deep neural networks (DNNs) are vulnerable to adversarial examples. In this paper, we propose a generative model to explore how to produce adversarial examples that can deceive multiple deep learning models simultaneously. Unlike most of popular adversarial attack algorithms, the one proposed in this paper is based on the Generative Adversarial Networks (GAN). It can quickly produce adversarial examples and perform black-box attacks on multi-model. To enhance the transferability of the samples generated by our approach, we use multiple neural networks in the training process. Experimental results on MNIST showed that our method can efficiently generate adversarial examples. Moreover, it can successfully attack various classes of deep neural networks at the same time, such as fully connected neural networks (FCNN), convolutional neural networks (CNN) and recurrent neural networks (RNN). We performed a black-box attack on VGG16 and the experimental results showed that when the test data classes are ten (0-9), the attack success rate is 97.68%, and when the test data classes are seven (0-6), the attack success rate is up to 98.25%.
引用
收藏
页码:641 / 649
页数:9
相关论文
共 50 条
  • [41] Imperceptible black-box waveform-level adversarial attack towards automatic speaker recognition
    Xingyu Zhang
    Xiongwei Zhang
    Meng Sun
    Xia Zou
    Kejiang Chen
    Nenghai Yu
    Complex & Intelligent Systems, 2023, 9 : 65 - 79
  • [42] A Black-Box Adversarial Attack via Deep Reinforcement Learning on the Feature Space
    Li, Lyue
    Rezapour, Amir
    Tzeng, Wen-Guey
    2021 IEEE CONFERENCE ON DEPENDABLE AND SECURE COMPUTING (DSC), 2021,
  • [43] Query-Efficient Black-Box Adversarial Attack With Customized Iteration and Sampling
    Shi, Yucheng
    Han, Yahong
    Hu, Qinghua
    Yang, Yi
    Tian, Qi
    IEEE TRANSACTIONS ON PATTERN ANALYSIS AND MACHINE INTELLIGENCE, 2023, 45 (02) : 2226 - 2245
  • [44] Detection Tolerant Black-Box Adversarial Attack Against Automatic Modulation Classification With Deep Learning
    Qi, Peihan
    Jiang, Tao
    Wang, Lizhan
    Yuan, Xu
    Li, Zan
    IEEE TRANSACTIONS ON RELIABILITY, 2022, 71 (02) : 674 - 686
  • [45] Imperceptible black-box waveform-level adversarial attack towards automatic speaker recognition
    Zhang, Xingyu
    Zhang, Xiongwei
    Sun, Meng
    Zou, Xia
    Chen, Kejiang
    Yu, Nenghai
    COMPLEX & INTELLIGENT SYSTEMS, 2023, 9 (01) : 65 - 79
  • [46] Improving the transferability of adversarial examples through black-box feature attacks
    Wang, Maoyuan
    Wang, Jinwei
    Ma, Bin
    Luo, Xiangyang
    NEUROCOMPUTING, 2024, 595
  • [47] Black-box Adversarial Attacks on Video Recognition Models
    Jiang, Linxi
    Ma, Xingjun
    Chen, Shaoxiang
    Bailey, James
    Jiang, Yu-Gang
    PROCEEDINGS OF THE 27TH ACM INTERNATIONAL CONFERENCE ON MULTIMEDIA (MM'19), 2019, : 864 - 872
  • [48] Black-box l1 and l2 Adversarial Attack Based on Genetic Algorithm
    Sun, Jiyuan
    Yu, Haibo
    Zhao, Jianjun
    2024 IEEE INTERNATIONAL CONFERENCE ON ARTIFICIAL INTELLIGENCE TESTING, AITEST, 2024, : 101 - 108
  • [49] High-transferability black-box attack of binary image segmentation via adversarial example augmentation
    Zhu, Xuebiao
    Chen, Wu
    Jiang, Qiuping
    DISPLAYS, 2025, 87
  • [50] Black-box transferable adversarial attacks based on ensemble advGAN
    Huang S.-N.
    Li Y.-X.
    Mao Y.-H.
    Ban A.-Y.
    Zhang Z.-Y.
    Jilin Daxue Xuebao (Gongxueban)/Journal of Jilin University (Engineering and Technology Edition), 2022, 52 (10): : 2391 - 2398