Deep Neural Networks (DNNs) exhibit vulnerability to adversarial examples, which exposes their fragility under semantic adversarial attacks. Semantic adversarial attacks can effectively manipulate the decisions of DNNs by introducing subtle modifications to critical semantic regions in images. These modifications present substantial challenges to existing defense mechanisms. However, current approaches to semantic adversarial attacks face difficulties in simultaneously achieving both stealthiness and a high success rate. To address this limitation, this paper proposes a novel semantic adversarial attack method, termed the Semantic Mask-Guided Diffusion Model (SMG-Diff). The proposed method first extracts critical semantic information from the target image and subsequently generates a semantic mask using the Salient Semantic Extraction Module (SSEM). During the reverse phase of the diffusion process, a Dynamic Mask Fusion Module (DMFM) is employed to adaptively adjust the mask, ensuring that the feature fusion process concentrates on the most critical regions of the image. By iteratively optimizing the mask and the feature fusion process, the method ultimately generates adversarial examples with enhanced stealthiness. Experimental results validate that SMG-Diff significantly enhances the stealthiness of adversarial examples while maintaining a high attack success rate.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

SMG-Diff: Adversarial Attack Method Based on Semantic Mask-Guided Diffusion

  • Yongliang Zhang,
  • Jing Liu

摘要

Deep Neural Networks (DNNs) exhibit vulnerability to adversarial examples, which exposes their fragility under semantic adversarial attacks. Semantic adversarial attacks can effectively manipulate the decisions of DNNs by introducing subtle modifications to critical semantic regions in images. These modifications present substantial challenges to existing defense mechanisms. However, current approaches to semantic adversarial attacks face difficulties in simultaneously achieving both stealthiness and a high success rate. To address this limitation, this paper proposes a novel semantic adversarial attack method, termed the Semantic Mask-Guided Diffusion Model (SMG-Diff). The proposed method first extracts critical semantic information from the target image and subsequently generates a semantic mask using the Salient Semantic Extraction Module (SSEM). During the reverse phase of the diffusion process, a Dynamic Mask Fusion Module (DMFM) is employed to adaptively adjust the mask, ensuring that the feature fusion process concentrates on the most critical regions of the image. By iteratively optimizing the mask and the feature fusion process, the method ultimately generates adversarial examples with enhanced stealthiness. Experimental results validate that SMG-Diff significantly enhances the stealthiness of adversarial examples while maintaining a high attack success rate.