<p>With the rapid development of deep neural networks in real-world applications, the vulnerability of deep neural networks has drawn a lot of interest in the research community. An important technique for probing the security issues of deep neural network models is to design as strong as possible attacks. Though existing white-box attacks can offer effective attacks, most of them are vulnerable to human inspection. On the other hand, some attacks are stealthy and imperceptible, but their damaging effect is largely weakened. It remains open challenge to reconcile the attack effectiveness and the imperceptibility. In this work, we propose a novel approach of crafting adversarial attacks. In particular, instead of attacking all image channels adopted in existing methods, we aim at specific color channel and the local region related to classification, wherein adversarial perturbations are exerted. In order to fool human visual system, we propose an improved bilinear interpolation approach to camouflage adversarial samples with enhanced resolution. The experiments on three benchmark datasets (MNIST, CIFAR10, IMAGENET-10) demonstrate that, compared to several strong attack methods, our model strikes a better balance between attack strength and human inspection. Moreover, the adversarial samples created by our method are more effective than those generated by the comparison methods in improving the robustness of the base classification model.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Color-channel adversarial attack with resolution based camouflaging

  • Guowei Li,
  • Ping Li,
  • Xinpeng Zhu

摘要

With the rapid development of deep neural networks in real-world applications, the vulnerability of deep neural networks has drawn a lot of interest in the research community. An important technique for probing the security issues of deep neural network models is to design as strong as possible attacks. Though existing white-box attacks can offer effective attacks, most of them are vulnerable to human inspection. On the other hand, some attacks are stealthy and imperceptible, but their damaging effect is largely weakened. It remains open challenge to reconcile the attack effectiveness and the imperceptibility. In this work, we propose a novel approach of crafting adversarial attacks. In particular, instead of attacking all image channels adopted in existing methods, we aim at specific color channel and the local region related to classification, wherein adversarial perturbations are exerted. In order to fool human visual system, we propose an improved bilinear interpolation approach to camouflage adversarial samples with enhanced resolution. The experiments on three benchmark datasets (MNIST, CIFAR10, IMAGENET-10) demonstrate that, compared to several strong attack methods, our model strikes a better balance between attack strength and human inspection. Moreover, the adversarial samples created by our method are more effective than those generated by the comparison methods in improving the robustness of the base classification model.