详细信息

Boosting transferability of adversarial samples via saliency distribution and frequency domain enhancement  ( SCI-EXPANDED收录 EI收录)  

文献类型:期刊文献

英文题名:Boosting transferability of adversarial samples via saliency distribution and frequency domain enhancement

作者:Wang, Yixuan[1];Hong, Wei[1];Zhang, Xueqin[1,2];Zhang, Qing[3];Gu, Chunhua[1]

机构:[1]East China Univ Sci & Technol, Sch Informat Sci & Engn, Shanghai 200237, Peoples R China;[2]Shanghai Key Lab Comp Software Evaluating & Testin, Shanghai 201112, Peoples R China;[3]Shanghai Inst Technol, Sch Comp Sci & Informat Engn, Shanghai 201418, Peoples R China

年份:2024

卷号:300

外文期刊名:KNOWLEDGE-BASED SYSTEMS

收录:;EI(收录号:20242716571250);WOS:【SCI-EXPANDED(收录号:WOS:001282626400001)】;

基金:This work was supported by the Major Program of National Fund of Philosopy and Social Science of China (grant number: 23&ZD142) .

语种:英文

外文关键词:Deep neural network; Black-box attack; Adversarial samples; Transferability

摘要:Deep neural networks (DNNs) perform excellently in various vision tasks, however, they are susceptible to the adversarial samples. These samples are crafted by injecting subtle perturbations into benign images that are barely detectable to humans. Due to the differences between the substitute model and target model, the efficacy of black-box attack still yield suboptimal results. To address this issue, we propose a black-box attack approach, SD-FI2M, 2 M, based on the momentum iterative fast gradient sign method, which can craft potent adversarial samples by inducing diverse inputs in the frequency domain and the saliency distribution of images. To enhance the diversity of input samples in frequency domain, a spectrum transformation technique utilizing the discrete cosine transform was used to craft adversarial samples with higher transferability. Further, Guided Grad-CAM was employed to obtain the saliency distribution of benign images, reducing indiscriminate damage to image features and alleviating the overfitting problem in adversarial samples. Extensive experiments on ImageNet have verified the superior attack performance and transferability of the proposed method.

参考文献:

正在载入数据...

版权所有©华东理工大学 重庆维普资讯有限公司 渝B2-20050021-7 
渝公网安备 50019002500408号 违法和不良信息举报中心