Generating Adversarial Examples With Shadow Model

Generating Adversarial Examples With Shadow Model
复制标题

使用影子模型生成对抗性示例

DOI:
10.1109/tii.2021.3139902
复制
发表时间:
2022-09
影响因子:
12.3
通讯作者:
Fu Xiao
Fu Xiao
中科院分区:
计算机科学1区
文献类型:
--
作者:
Rui Zhang;Hui Xia;Chunqiang Hu;Cheng Zhang;Chao Liu;Fu Xiao

文献摘要

相似文献

减少对对象模型的查询次数是当前黑盒对抗攻击方法研究的热点。为了解决这个问题,在本文中,我们提出了使用阴影模型(GASM)生成对抗性示例,将对对象模型的查询数量转移到阴影模型。该方法首先根据分类器的鲁棒性和可移植性确定阴影模型,并通过构造对抗数据集来微调阴影模型的决策边界。其次,访问阴影模型,并通过最大化目标类(当前类以外的任何类)的输出概率来修改图像梯度信息来构建对抗性示例。最后,结果表明,当选择AlexNet(MNIST),VGG-19(CIFAR 10)和MobileNet v2(Tiny ImageNet)作为影子模型时,GASM具有最强的可移植性,并且优于白盒攻击。
The reduction in the number of queries to the object model is a hot topic in the current research of black-box adversarial attack methods. To solve this problem, in this article, we propose generating adversarial examples with shadow model (GASM) that shifts the number of queries to the object model to the shadow model. The method first determines the shadow model based on the robustness and transferability of classifiers and fine-tunes the decision boundary of the shadow model by constructing adversarial datasets. Second, accesses the shadow model and constructs adversarial examples by maximizing the output probability of the targeted class (any class other than the current one) to modify the image gradient information. Finally, the results show that GASM has the strongest transferability and outperforms white-box attacks when AlexNet (MNIST), VGG-19 (CIFAR10), and MobileNet v2 (Tiny ImageNet) are selected as shadow models.