详细信息
Black-box targeted adversarial attacks for deep neural networks ( SCI-EXPANDED收录 EI收录)
文献类型:期刊文献
英文题名:Black-box targeted adversarial attacks for deep neural networks
作者:Zhang, Xueqin[1];Geng, Peilin[1];Hong, Wei[1];Wang, Yixuan[1];Gu, Chunhua[2]
机构:[1]East China Univ Sci & Technol, Shanghai 200237, Peoples R China;[2]Shanghai Univ Elect Power, Shanghai 201306, Peoples R China
年份:2025
卷号:652
外文期刊名:NEUROCOMPUTING
收录:;EI(收录号:20253018853501);WOS:【SCI-EXPANDED(收录号:WOS:001551481500001)】;
基金:Acknowledgement This work was supported by the Major Program of National Fund of Philosophy and Social Science of China (grant number: 23&ZD142) .
语种:英文
外文关键词:Deep neural network; Black-box attack; Adversarial samples; Transferability
摘要:Deep neural networks have exhibited exceptional performance across a wide spectrum of applications. However, they remain vulnerable to adversarial samples. To address the issue of poor transferability of adversarial samples in cross-domain targeted attacking scenarios, we propose a novel method named Cross Domain Dual Training (CD-DT) utilizing Generative Adversarial Networks (GANs). Within this framework, the generative adversarial network comprises one generator and two trainable discriminators. To improve the transferability of adversarial samples in cross domain attacks, we incorporate three techniques into the training process of GAN. The differential minimization training technique with three distinct loss functions is employed to amplify the efficacy of adversarial samples against different target models. The Cross-domain Cross-Entropy (CCE) function is applied to replace the Cross-Entropy function used in classical GANs to diminish the sensitivity of the generated perturbations to the underlying data distribution. In addition, we introduce a data distribution alignment method that utilizes three loss functions to ensure the generated adversarial samples keep the similar distribution with the target samples from both global and local perspectives, thereby improving their transferability to the target class. Experimental results demonstrate that our method significantly enhances the transferability of adversarial samples in complex cross-domain and cross-model scenarios compared to existing baseline methods.
参考文献:
正在载入数据...
