Universal adversarial perturbations generative network

被引:0
作者
Zheng Wang
Yang Yang
Jingjing Li
Xiaofeng Zhu
机构
[1] University of Electronic Science and Technology of China,School of Computer Science and Engineering
来源
World Wide Web | 2022年 / 25卷
关键词
Universal adversarial perturbations; Adversarial attack; Generative model; Image captioning; Image classification;
D O I
暂无
中图分类号
学科分类号
摘要
Recently, adversarial attack against Deep Neural Networks (DNN) have drawn very keen interest of researchers. Existence of universal adversarial perturbations could empower the cases where could not generate the image-dependent adversarial examples, which are known to be very successful on image classification. Previous work are mainly optimization-based, which take a long time to search perturbations, and the obtained adversarial examples are not so real and can be easily defensed. Moreover the researches on universal adversarial perturbation against vision-language systems are few. In our work, we novelly construct a GenerAtive Network for Universal Adversarial Perturbations, dubbed as UAP-GAN, to study the robustness of image classification and captioning systems, based on convolutional neural networks and plus recurrent neural networks, respectively. Specifically, our proposed UAP-GAN improves the framework of GAN to compute universal adversarial perturbations, with the input of a fixed random noise. Comparing to existing methods, our UAP-GAN method has four main characteristics: fast generation, high attack success rate, close to natural image, yet difficult to defense. In addition, our proposed model could produce image-agnostic perturbations for targeted and non-targeted attacks, according to the selected scene. In the end, our comprehensive experiments on MSCOCO and ImageNet, demonstrate the clear superiority to the existing work, and also prove that our UAP-GAN architecture could effectively fool the image captioning and classification models with splendid results, yet avoid the redesign of framework for different tasks.
引用
收藏
页码:1725 / 1746
页数:21
相关论文
共 18 条
[1]  
Arnab A(2020)On the robustness of semantic segmentation models to adversarial attacks IEEE Trans. Pattern Anal. Mach. Intell. 42 3040-3053
[2]  
Miksik O(2020)Black-box adversarial sample generation based on differential evolution J. Syst. Softw. 170 110767-2324
[3]  
Torr PHS(1998)Gradient-based learning applied to document recognition Proc. IEEE 86 2278-65
[4]  
Junyu L(2019)Multi-scale aggregation network for temporal action proposals Pattern Recogn. Lett. 122 60-undefined
[5]  
Lei X(undefined)undefined undefined undefined undefined-undefined
[6]  
Yingqi L(undefined)undefined undefined undefined undefined-undefined
[7]  
Xiangyu Z(undefined)undefined undefined undefined undefined-undefined
[8]  
Lecun Y(undefined)undefined undefined undefined undefined-undefined
[9]  
Bottou L(undefined)undefined undefined undefined undefined-undefined
[10]  
Bengio Y(undefined)undefined undefined undefined undefined-undefined