skip to main content
Primo Search
Search in: Busca Geral

Universal Adversarial Attack on Attention and the Resulting Dataset DAmageNet

Chen, Sizhe ; He, Zhengbao ; Sun, Chengjin ; Yang, Jie ; Huang, Xiaolin

IEEE transactions on pattern analysis and machine intelligence, 2022-04, Vol.44 (4), p.2188-2197 [Periódico revisado por pares]

United States: IEEE

Texto completo disponível

Citações Citado por
  • Título:
    Universal Adversarial Attack on Attention and the Resulting Dataset DAmageNet
  • Autor: Chen, Sizhe ; He, Zhengbao ; Sun, Chengjin ; Yang, Jie ; Huang, Xiaolin
  • Assuntos: Adversarial attack ; Algorithms ; Attention ; Benchmarking ; black-box attack ; DAmageNet ; Error analysis ; Heating systems ; Neural networks ; Neural Networks, Computer ; Perturbation methods ; Semantics ; Training ; transferability ; Visualization
  • É parte de: IEEE transactions on pattern analysis and machine intelligence, 2022-04, Vol.44 (4), p.2188-2197
  • Notas: ObjectType-Article-1
    SourceType-Scholarly Journals-1
    ObjectType-Feature-2
    content type line 23
  • Descrição: Adversarial attacks on deep neural networks (DNNs) have been found for several years. However, the existing adversarial attacks have high success rates only when the information of the victim DNN is well-known or could be estimated by the structure similarity or massive queries. In this paper, we propose to Attack on Attention (AoA), a semantic property commonly shared by DNNs. AoA enjoys a significant increase in transferability when the traditional cross entropy loss is replaced with the attention loss. Since AoA alters the loss function only, it could be easily combined with other transferability-enhancement techniques and then achieve SOTA performance. We apply AoA to generate 50000 adversarial samples from ImageNet validation set to defeat many neural networks, and thus name the dataset as DAmageNet . 13 well-trained DNNs are tested on DAmageNet, and all of them have an error rate over 85 percent. Even with defenses or adversarial training, most models still maintain an error rate over 70 percent on DAmageNet. DAmageNet is the first universal adversarial dataset. It could be downloaded freely and serve as a benchmark for robustness testing and adversarial training.
  • Editor: United States: IEEE
  • Idioma: Inglês

Buscando em bases de dados remotas. Favor aguardar.