EAD: Elastic-Net Attacks to Deep Neural Networks via Adversarial Examples

EAD: Elastic-Net Attacks to Deep Neural Networks via Adversarial Examples
复制标题

DOI:
10.1609/aaai.v32i1.11302
复制
发表时间:
2017-09
期刊:
ArXiv
影响因子:
--
通讯作者:
Pin-Yu Chen;Yash Sharma;Huan Zhang;Jinfeng Yi;Cho-Jui Hsieh
Pin-Yu Chen;Yash Sharma;Huan Zhang;Jinfeng Yi;Cho-Jui Hsieh
中科院分区:
其他
文献类型:
--
作者:
Pin-Yu Chen;Yash Sharma;Huan Zhang;Jinfeng Yi;Cho-Jui Hsieh

文献摘要

被引文献

相似文献

最近的研究强调了深度神经网络(DNN)对对抗性示例的脆弱性-视觉上无法区分的对抗性图像很容易被制作出来,导致训练有素的模型错误分类。现有的制作对抗性示例的方法基于L2和L∞失真度量。然而,尽管L1失真解释了总的变化并鼓励扰动的稀疏性,但几乎没有开发出基于L1的对抗性示例。在本文中,我们将通过对抗性示例攻击DNN的过程表述为弹性网络正则化优化问题。我们对DNN(EAD)的弹性网络攻击具有面向L1的对抗性示例,并包括最先进的L2攻击作为特例。在MNIST,CIFAR 10和ImageNet上的实验结果表明,EAD可以产生一组具有小L1失真的对抗性示例,并且在不同的攻击场景中获得与最先进方法相似的攻击性能。更重要的是,EAD提高了攻击的可转移性,并补充了DNN的对抗性训练,提出了在对抗性机器学习中利用L1失真和DNN安全影响的新见解。
Recent studies have highlighted the vulnerability of deep neural networks (DNNs) to adversarial examples — a visually indistinguishable adversarial image can easily be crafted to cause a well-trained model to misclassify. Existing methods for crafting adversarial examples are based on L2 and L∞ distortion metrics. However, despite the fact that L1 distortion accounts for the total variation and encourages sparsity in the perturbation, little has been developed for crafting L1-based adversarial examples. In this paper, we formulate the process of attacking DNNs via adversarial examples as an elastic-net regularized optimization problem. Our elastic-net attacks to DNNs (EAD) feature L1-oriented adversarial examples and include the state-of-the-art L2 attack as a special case. Experimental results on MNIST, CIFAR10 and ImageNet show that EAD can yield a distinct set of adversarial examples with small L1 distortion and attains similar attack performance to the state-of-the-art methods in different attack scenarios. More importantly, EAD leads to improved attack transferability and complements adversarial training for DNNs, suggesting novel insights on leveraging L1 distortion in adversarial machine learning and security implications of DNNs.