A Sparsity-Limitation-Based High-Dimensional Distribution Searching Algorithm for Adversarial Attack

Author:

Zhu Chenxi1ORCID,Wang Haobo1ORCID,Zhuang Yan1ORCID,Li Jie12ORCID,Cao Yangjie1ORCID

Affiliation:

1. School of Cyber Science and Engineering, Zhengzhou University, Zhengzhou 450000, China

2. Department of Computer Science and Engineering, Shanghai Jiaotong University, Shanghai 200240, China

Abstract

Deep neural networks-based image classification systems could suffer from adversarial attack algorithms, which generate input examples by adding deliberately crafted yet imperceptible noise to original inputs. To reduce the impact on human visual sense and to ensure adversarial attack ability, the input image needs to be modified by pixels in considerable iterations which is time consuming. By using sparse mapping network to map the input into a higher dimensional space, searching space of adversarial perturbation distribution is enlarged to better acquire perturbation information. Taking both searching speed and searching effectiveness into consideration, sparsity limitation is introduced to suppress unnecessary neurons during parameter updating process. Based on different eye sensitivity of different colors, maps of each color channel are disturbed by perturbations with different strengths to reduce visual perception. Numerical experiments confirm that compared with the state-of-the-art adversarial attack algorithms, the proposed SparseAdv performs a relatively high attack ability, better imperceptible visualization, and faster generation speed.

Funder

Collaborative Innovation Major Project of Zhengzhou

Publisher

Hindawi Limited

Subject

Electrical and Electronic Engineering,Instrumentation,Control and Systems Engineering

Reference35 articles.

1. A survey of image classification methods and techniques for improving classification performance

2. ImageNet classification with deep convolutional neural networks;A. Krizhevsky;Advances in Neural Information Processing Systems,2012

3. Delving deep into rectifiers: surpassing human-level performance on ImageNet classification;K. He

4. Convolutional Neural Networks for Speech Recognition

5. Object Detection With Deep Learning: A Review

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3