4.6 Article

Fast-UAP: An algorithm for expediting universal adversarial perturbation generation using the orientations of perturbation vectors

期刊

NEUROCOMPUTING
卷 422, 期 -, 页码 109-117

出版社

ELSEVIER
DOI: 10.1016/j.neucom.2020.09.052

关键词

Adversarial machine learning; Adversarial perturbation; Convolutional neural network (CNN); Image classification

资金

  1. State Scholarship Fund of the China Scholarship Council [201606895018]
  2. Shanghai Engineering Research Center of Intelligent Computing System [19DZ2252600]

向作者/读者索取更多资源

An optimized algorithm based on the orientations of perturbation vectors is proposed to enhance the performance of generating universal perturbations in CNN models. Experimental results show that the proposed algorithm can generate universal perturbations in a shorter time with a higher fooling-rate increment in both white-box and black-box attacks compared to the original algorithm.
Convolutional neural networks (CNNs), which are popular machine-learning tools, are being applied in various tasks. However, CNN models are vulnerable to universal perturbations, which despite being usu-ally quasi-imperceptible to the human eye can cause natural images to be misclassified with high probability. The original algorithm of generating universal perturbations (the algorithm is called UAP for brevity) only aggregates minimal perturbations in each iteration without considering the orientations of perturbation vectors; consequently, the magnitude of the universal perturbation cannot efficiently increase at each iteration, thereby resulting in slow universal perturbation generation. Hence, we propose an optimized algorithm to enhance the performance of generating universal perturbations based on the orientations of perturbation vectors. At each iteration, rather than choosing the minimal perturbation vector, we choose the perturbation whose orientation is similar to that of the current universal perturbation; therefore, the magnitude of the aggregation of both the perturbations will be maximized. The experimental results show that compared with UAP, we could generate universal perturbations in a shorter time using a smaller number of training images. Furthermore, we empirically observed that compared with the universal perturbations generated using UAP, the ones generated using our proposed algorithm achieved an average fooling-rate increment of 9% in white-box and black-box attacks. (c) 2020 Elsevier B.V. All rights reserved.

作者

我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。

评论

主要评分

4.6
评分不足

次要评分

新颖性
-
重要性
-
科学严谨性
-
评价这篇论文

推荐

暂无数据
暂无数据