A Novel DNN Object Contour Attack on Image Recognition
摘要
Deep neural networks (DNNs) have diverse applications due to their ability to learn features. However, recent studies have revealed that DNNs are susceptible to adversarial examples. Currently, the primary focus of research on generating adversarial examples is to improve the attack success rate (ASR) while minimizing the perturbation size. Through the visualization of heatmaps, previous studies have identified that the feature extraction capability of DNNs arises from their precise location of object contours and appropriate attention given to those areas. Therefore, perturbations in adversarial examples can weaken the location of object contours in deep hidden layers and reduce the attention scope of object areas, leading to successful attacks. Inspired by this observation, this chapter introduces our method, a novel adversarial attack based on the attention perturbation technique, which encompasses channel-spatial attention and pixel-spatial attention. The former reduces the area of concern for DNNs, while the latter achieves the error location of object contours. By targeting positions that are more vulnerable in legitimate examples using the attention perturbation technique, our method achieves a higher ASR with fewer perturbations compared to state-of-the-art adversarial attacks.