A novel approach to generating high-resolution adversarial examples

被引:0
作者
Xianjin Fang
Zhiwei Li
Gaoming Yang
机构
[1] Anhui University of Science and Technology,
来源
Applied Intelligence | 2022年 / 52卷
关键词
Adversarial examples; Generative adversarial nets; Semiwhite-box attack; Computer vision;
D O I
暂无
中图分类号
学科分类号
摘要
Deep neural networks (DNNs) have improved expressive performance in many artificial intelligence (AI) fields in recent years. However, they can easily induce incorrect behavior due to adversarial examples. The state-of-the-art strategies for generating adversarial examples were established as generative adversarial nets (GAN). Due to a large amount of data and the high computational resources required, previous GAN-based work has only generated adversarial examples for small datasets, resulting in a less favorable visualization of the generated images. To address this problem, we propose a feasible approach, which improves on the AdvGAN framework through data augmentation, combined with PCA and KPCA to map the input instance’s main features onto the latent variables. Experimental results indicate that our approach can generate more natural perturbations on high-resolution images while maintaining 96% + of the features of the original input instance. Moreover, we measured 90.30% attack success rates on CIFAR-10 against the target model ResNet152, a small improvement compared to 88.69% for AdvGAN. We applied the same idea to ImageNet and LSUN, and the results showed that it not only achieves a high attack success rate,but can generate strongly semantically adversarial examples with better transferability on prevailing DNNs classification models. We also show that our approach yields competitive results compared to sensitivity analysis-based or optimization-based attacks notable in the literature.
引用
收藏
页码:1289 / 1305
页数:16
相关论文
共 40 条
  • [1] McKinney SM(2020)International evaluation of an AI system for breast cancer screening Nature 577 89-94
  • [2] Sieniek M(2020)Hierarchical LSTMs with adaptive attention for visual captioning IEEE Trans Pattern Anal Mach Intell 42 1112-1131
  • [3] Godbole V(2019)A survey on image data augmentation for deep learning J Big Data 6 60-234
  • [4] Godwin J(2021)Less complexity one-class classification approach using construction error of convolutional image transformation network Inf Sci 560 217-undefined
  • [5] Antropova N(undefined)undefined undefined undefined undefined-undefined
  • [6] Ashrafian H(undefined)undefined undefined undefined undefined-undefined
  • [7] Back T(undefined)undefined undefined undefined undefined-undefined
  • [8] Chesus M(undefined)undefined undefined undefined undefined-undefined
  • [9] Corrado GS(undefined)undefined undefined undefined undefined-undefined
  • [10] Darzi A(undefined)undefined undefined undefined undefined-undefined