基于沙漏形补丁攻击的对抗样本生成方法

    Adversarial example generation method based on hourglass-shaped patch attack

    • 摘要: 在对抗样本生成领域,一种较为实用的方法是构建一个低感知的局部扰动补丁附加在原始样本上,从而误导模型输出错误的分类结果。然而,现有的基于补丁的对抗攻击侧重于正方形、矩形或网格的局部补丁方法,忽略了补丁对图像总体特征的影响,且存在单一性损失的问题。鉴于此,本文提出一种新颖的基于沙漏形补丁攻击的对抗样本生成方法。具体来说,所提沙漏补丁由两个相同的、顶点相对的三角形连接而成,并且其中的每条线段尽可能设计得足够细和长,以便减少视觉扰动和扩大样本搜索空间。同时,设计了4种补丁颜色填充方案以及一种特征空间损失进一步提高攻击性能。基于ImageNet、CIFAR-10和CIFAR-100三个数据集的实验结果表明,该方法与现有方法相比,在攻击成功率和查询效率方面展现出优越性能, 在ImageNet数据集下攻击Inception_v3目标模型时,非定向攻击的攻击成功率提高2.82%,而平均查询次数减少约42次。

       

      Abstract: In the field of adversarial example generation, one practical approach is to construct a low perception local perturbation patch attached to the original example, thereby misleading the model to output incorrect classification results. However, existing patch based adversarial attacks focus on local patch methods for squares, rectangles, or grids, ignoring the impact of patch on the overall image features and suffering from singularity loss. In view of this, a novel adversarial example generation method based on Hourglass-Shaped Patch Attack (HSPA) is proposed. Specifically, the hourglass patch is composed of two identical triangles with opposite vertices connected, and each line segment is designed as thin and long as possible to reduce visual perturbation and expand the example search space. At the same time, four patch color filling schemes and a feature space loss are designed to further improve attack performance. The experimental results based on three datasets(ImageNet, CIFAR-10, CIFAR-100) show that compared with existing methods, HSPA exhibits superior performance in attack success rate and query efficiency.

       

    /

    返回文章
    返回