Generating Adversarial Examples With Shadow Model
Generating Adversarial Examples With Shadow Model
复制标题
使用影子模型生成对抗性示例
DOI:
10.1109/tii.2021.3139902
复制
发表时间:
2022-09
影响因子:
12.3
通讯作者:
Fu Xiao
中科院分区:
文献类型:
--
作者:
Rui Zhang;Hui Xia;Chunqiang Hu;Cheng Zhang;Chao Liu;Fu Xiao
The reduction in the number of queries to the object model is a hot topic in the current research of black-box adversarial attack methods. To solve this problem, in this article, we propose generating adversarial examples with shadow model (GASM) that shifts the number of queries to the object model to the shadow model. The method first determines the shadow model based on the robustness and transferability of classifiers and fine-tunes the decision boundary of the shadow model by constructing adversarial datasets. Second, accesses the shadow model and constructs adversarial examples by maximizing the output probability of the targeted class (any class other than the current one) to modify the image gradient information. Finally, the results show that GASM has the strongest transferability and outperforms white-box attacks when AlexNet (MNIST), VGG-19 (CIFAR10), and MobileNet v2 (Tiny ImageNet) are selected as shadow models.