Color-channel adversarial attack with resolution based camouflaging
摘要
With the rapid development of deep neural networks in real-world applications, the vulnerability of deep neural networks has drawn a lot of interest in the research community. An important technique for probing the security issues of deep neural network models is to design as strong as possible attacks. Though existing white-box attacks can offer effective attacks, most of them are vulnerable to human inspection. On the other hand, some attacks are stealthy and imperceptible, but their damaging effect is largely weakened. It remains open challenge to reconcile the attack effectiveness and the imperceptibility. In this work, we propose a novel approach of crafting adversarial attacks. In particular, instead of attacking all image channels adopted in existing methods, we aim at specific color channel and the local region related to classification, wherein adversarial perturbations are exerted. In order to fool human visual system, we propose an improved bilinear interpolation approach to camouflage adversarial samples with enhanced resolution. The experiments on three benchmark datasets (MNIST, CIFAR10, IMAGENET-10) demonstrate that, compared to several strong attack methods, our model strikes a better balance between attack strength and human inspection. Moreover, the adversarial samples created by our method are more effective than those generated by the comparison methods in improving the robustness of the base classification model.