CAG: A Real-time Low-cost Enhanced-robustness High-transferability Content-aware Adversarial Attack Generator

CAG: A Real-time Low-cost Enhanced-robustness High-transferability Content-aware Adversarial Attack Generator
复制标题

CAG:实时低成本增强鲁棒性高可转移性内容感知对抗攻击生成器

DOI:
--
复制
发表时间:
2019
期刊:
AAAI Conference on Artificial Intelligence
影响因子:
--
通讯作者:
Bo Yuan
Bo Yuan
中科院分区:
--
文献类型:
--
作者:
Huy Phan;Yi Xie;Siyu Liao;Jie Chen;Bo Yuan

文献摘要

被引文献

相似文献

深度神经网络(DNN)很容易受到对抗性攻击,尽管它们在许多人工智能领域取得了巨大的成功。对抗性攻击是一种通过向合法输入添加不可感知的扰动来引起预期的误分类的方法。到目前为止,研究人员已经开发了许多类型的对抗性攻击方法。然而,从实际部署的角度来看,这些方法遭受的几个缺点,如攻击生成时间长,内存成本高,鲁棒性不足和低可移植性。为了解决这些问题,我们提出了一个内容感知的对抗攻击生成器(CAG),以实现实时,低成本,增强鲁棒性和高可移植性的对抗攻击。首先,作为一种基于生成模型的攻击,与PGD和C&W等最先进的攻击相比,CAG在生成对抗性示例方面表现出显着的加速(至少500倍)。此外,CAG只需要一个单一的生成模型来执行有针对性的攻击任何目标类。由于CAG将标签信息编码到可训练的嵌入层中,因此它不同于先前基于生成模型的对抗性攻击,后者针对n个不同的目标类使用n个不同的生成模型副本。因此,CAG显著降低了生成对抗性示例所需的内存成本。此外,CAG可以通过在训练过程中整合类激活图信息来生成专注于输入关键区域的对抗性扰动,从而提高CAG攻击对最新对抗性防御的鲁棒性。此外,通过在生成扰动的过程中引入随机丢弃,CAG在黑盒攻击场景中表现出在不同DNN分类器模型之间的高可移植性。在不同数据集和DNN模型上进行的大量实验已经验证了CAG的实时性,低成本,增强的鲁棒性和高可移植性。
Deep neural networks (DNNs) are vulnerable to adversarial attack despite their tremendous success in many artificial intelligence fields. Adversarial attack is a method that causes the intended misclassfication by adding imperceptible perturbations to legitimate inputs. To date, researchers have developed numerous types of adversarial attack methods. However, from the perspective of practical deployment, these methods suffer from several drawbacks such as long attack generating time, high memory cost, insufficient robustness and low transferability. To address the drawbacks, we propose a Content-aware Adversarial Attack Generator (CAG) to achieve real-time, low-cost, enhanced-robustness and high-transferability adversarial attack. First, as a type of generative model-based attack, CAG shows significant speedup (at least 500 times) in generating adversarial examples compared to the state-of-the-art attacks such as PGD and C&W. Furthermore, CAG only needs a single generative model to perform targeted attack to any targeted class. Because CAG encodes the label information into a trainable embedding layer, it differs from prior generative model-based adversarial attacks that use n different copies of generative models for n different targeted classes. As a result, CAG significantly reduces the required memory cost for generating adversarial examples. Moreover, CAG can generate adversarial perturbations that focus on the critical areas of input by integrating the class activation maps information in the training process, and hence improve the robustness of CAG attack against the state-of-art adversarial defenses. In addition, CAG exhibits high transferability across different DNN classifier models in black-box attack scenario by introducing random dropout in the process of generating perturbations. Extensive experiments on different datasets and DNN models have verified the real-time, low-cost, enhanced-robustness, and high-transferability benefits of CAG.