Abstract:
In the field of adversarial example generation, one practical approach is to construct a low perception local perturbation patch attached to the original example, thereby misleading the model to output incorrect classification results. However, existing patch based adversarial attacks focus on local patch methods for squares, rectangles, or grids, ignoring the impact of patch on the overall image features and suffering from singularity loss. In view of this, a novel adversarial example generation method based on Hourglass-Shaped Patch Attack (HSPA) is proposed. Specifically, the hourglass patch is composed of two identical triangles with opposite vertices connected, and each line segment is designed as thin and long as possible to reduce visual perturbation and expand the example search space. At the same time, four patch color filling schemes and a feature space loss are designed to further improve attack performance. The experimental results based on three datasets(ImageNet, CIFAR-10, CIFAR-100) show that compared with existing methods, HSPA exhibits superior performance in attack success rate and query efficiency.