Reinforced Adversarial Attacks on Deep Neural Networks Using ADMM

Reinforced Adversarial Attacks on Deep Neural Networks Using ADMM
复制标题

DOI:
10.1109/globalsip.2018.8646651
复制
发表时间:
2018-11
期刊:
2018 IEEE Global Conference on Signal and Information Processing (GlobalSIP)
影响因子:
--
通讯作者:
Pu Zhao;Kaidi Xu;Tianyun Zhang;M. Fardad;Yanzhi Wang;X. Lin
Pu Zhao;Kaidi Xu;Tianyun Zhang;M. Fardad;Yanzhi Wang;X. Lin
中科院分区:
其他
文献类型:
--
作者:
Pu Zhao;Kaidi Xu;Tianyun Zhang;M. Fardad;Yanzhi Wang;X. Lin

文献摘要

相似文献

随着深度学习渗透到广泛的应用领域,评估深度神经网络(DNN)在对抗性攻击下的鲁棒性至关重要,特别是对于一些安全关键型应用。为了更好地理解 DNN 的安全特性,我们提出了一个基于 ADMM(乘数交替方向法)构建对抗性示例的通用框架。这个通用框架只需稍作改动即可实现 L2 和 L0 攻击。与 C&W 攻击相比,我们的 ADMM 攻击需要更少的错误分类失真。我们的ADMM攻击还能够突破防御蒸馏和对抗训练等防御,并提供强大的攻击可转移性。
As deep learning penetrates into wide application domains, it is essential to evaluate the robustness of deep neural networks (DNNs) under adversarial attacks, especially for some security-critical applications. To better understand the security properties of DNNs, we propose a general framework for constructing adversarial examples, based on ADMM (Alternating Direction Method of Multipliers). This general framework can be adapted to implement L2 and L0 attacks with minor changes. Our ADMM attacks require less distortion for incorrect classification compared with C&W attacks. Our ADMM attack is also able to break defenses such as defensive distillation and adversarial training, and provide strong attack transferability.