One pixel attack for fooling deep neural networks
arXiv:1710.08864 · doi:10.1109/TEVC.2019.2890858
Abstract
Recent research has revealed that the output of Deep Neural Networks (DNN) can be easily altered by adding relatively small perturbations to the input vector. In this paper, we analyze an attack in an extremely limited scenario where only one pixel can be modified. For that we propose a novel method for generating one-pixel adversarial perturbations based on differential evolution (DE). It requires less adversarial information (a black-box attack) and can fool more types of networks due to the inherent features of DE. The results show that 67.97% of the natural images in Kaggle CIFAR-10 test dataset and 16.04% of the ImageNet (ILSVRC 2012) test images can be perturbed to at least one target class by modifying just one pixel with 74.03% and 22.91% confidence on average. We also show the same vulnerability on the original CIFAR-10 dataset. Thus, the proposed attack explores a different take on adversarial machine learning in an extreme limited scenario, showing that current DNNs are also vulnerable to such low dimension attacks. Besides, we also illustrate an important application of DE (or broadly speaking, evolutionary computation) in the domain of adversarial machine learning: creating tools that can effectively generate low-cost adversarial attacks against neural networks for evaluating robustness.
References in corpus (3)
Cited by in corpus (113)
- Deep learning in nano-photonics: inverse design and beyond
- On Mean Absolute Error for Deep Neural Network Based Vector-to-Vector Regression
- AdvHat: Real-world adversarial attack on ArcFace Face ID system
- Securing Connected & Autonomous Vehicles: Challenges Posed by Adversarial Machine Learning and The Way Forward
- Adversarial Examples: Opportunities and Challenges
- Multi-Objective Counterfactual Explanations
- Adversarial Example Detection for DNN Models: A Review and Experimental Comparison
- Adversarial attacks and defenses in explainable artificial intelligence: A survey
- Adversarial Machine Learning in Image Classification: A Survey Towards the Defender's Perspective
- Adversarial Attack Vulnerability of Medical Image Analysis Systems: Unexplored Factors
- RouteNet-Fermi: Network Modeling with Graph Neural Networks
- Physical Adversarial Attack meets Computer Vision: A Decade Survey
- Deep Learning Methods for Solving Linear Inverse Problems: Research Directions and Paradigms
- Towards quantum enhanced adversarial robustness in machine learning
- Hardening Random Forest Cyber Detectors Against Adversarial Attacks
- Attacking Recommender Systems with Augmented User Profiles
- Towards Understanding and Boosting Adversarial Transferability from a Distribution Perspective
- A Survey on Reservoir Computing and its Interdisciplinary Applications Beyond Traditional Machine Learning
- Single Node Injection Attack against Graph Neural Networks
- Shilling Black-box Recommender Systems by Learning to Generate Fake User Profiles
- Human-Centric Multimodal Machine Learning: Recent Advances and Testbed on AI-based Recruitment
- Survey on Adversarial Attack and Defense for Medical Image Analysis: Methods and Challenges
- Inspect, Understand, Overcome: A Survey of Practical Methods for AI Safety
- Towards Adversarial Realism and Robust Learning for IoT Intrusion Detection and Classification
- Physical Knowledge Enhanced Deep Neural Network for Sea Surface Temperature Prediction
- Adaptative Perturbation Patterns: Realistic Adversarial Learning for Robust Intrusion Detection
- A black-box adversarial attack for poisoning clustering
- Advancing diagnostic performance and clinical usability of neural networks via adversarial training and dual batch normalization
- SoK: Realistic Adversarial Attacks and Defenses for Intelligent Network Intrusion Detection
- Get your Foes Fooled: Proximal Gradient Split Learning for Defense against Model Inversion Attacks on IoMT data
- Multi-SpacePhish: Extending the Evasion-space of Adversarial Attacks against Phishing Website Detectors using Machine Learning
- Pixle: a fast and effective black-box attack based on rearranging pixels
- DARWIN: Survival of the Fittest Fuzzing Mutators
- Towards a Robust and Trustworthy Machine Learning System Development: An Engineering Perspective
- Generating Anthropomorphic Phantoms Using Fully Unsupervised Deformable Image Registration with Convolutional Neural Networks
- DLA: Dense-Layer-Analysis for Adversarial Example Detection
- Mitigating Adversarial Gray-Box Attacks Against Phishing Detectors
- An Improved Genetic Algorithm and Its Application in Neural Network Adversarial Attack
- Adversarial Attacks on Video Object Segmentation with Hard Region Discovery
- Tensor networks for interpretable and efficient quantum-inspired machine learning
- Discriminator-Free Generative Adversarial Attack
- Black-box adversarial attacks using Evolution Strategies
- Rank List Sensitivity of Recommender Systems to Interaction Perturbations
- Physical Adversarial Attacks for Surveillance: A Survey
- Algorithmic Ways of Seeing: Using Object Detection to Facilitate Art Exploration
- A Black-box Attack on Neural Networks Based on Swarm Evolutionary Algorithm
- TrojanZoo: Towards Unified, Holistic, and Practical Evaluation of Neural Backdoors
- Wild Networks: Exposure of 5G Network Infrastructures to Adversarial Examples
- Brain Programming is Immune to Adversarial Attacks: Towards Accurate and Robust Image Classification using Symbolic Learning
- How Robust are Discriminatively Trained Zero-Shot Learning Models?
- Improving adversarial robustness of deep neural networks by using semantic information
- Quantitative Comparison of Planar Coded Aperture Imaging Reconstruction Methods
- SPAA: Stealthy Projector-based Adversarial Attacks on Deep Image Classifiers
- Smooth Adversarial Examples
- Evolutionary approaches to explainable machine learning
- Road Context-aware Intrusion Detection System for Autonomous Cars
- An Evolutionary, Gradient-Free, Query-Efficient, Black-Box Algorithm for Generating Adversarial Instances in Deep Networks
- Deep learning for nano-photonic materials -- The solution to everything!?
- Robustness Testing for Multi-Agent Reinforcement Learning: State Perturbations on Critical Agents
- Experimental demonstration of adversarial examples in learning topological phases
- The Inherent Adversarial Robustness of Analog In-Memory Computing
- QuerySnout: Automating the Discovery of Attribute Inference Attacks against Query-Based Systems
- Towards a robust and reliable deep learning approach for detection of compact binary mergers in gravitational wave data
- PatchBackdoor: Backdoor Attack against Deep Neural Networks without Model Modification
- Shifting Capsule Networks from the Cloud to the Deep Edge
- The Feasibility and Inevitability of Stealth Attacks
- Defence against adversarial attacks using classical and quantum-enhanced Boltzmann machines
- Cloud-based XAI Services for Assessing Open Repository Models Under Adversarial Attacks
- Determining Sequence of Image Processing Technique (IPT) to Detect Adversarial Attacks
- Dynamics-aware Adversarial Attack of Adaptive Neural Networks
- Effective Universal Unrestricted Adversarial Attacks using a MOE Approach
- Adversarial Machine Learning Phases of Matter
- One-Pixel Attack Deceives Computer-Assisted Diagnosis of Cancer
- Adversarial Robustness Guarantees for Quantum Classifiers
- The Boundaries of Verifiable Accuracy, Robustness, and Generalisation in Deep Learning
- Adjust-free adversarial example generation in speech recognition using evolutionary multi-objective optimization under black-box condition
- A Systematic Evaluation of Adversarial Attacks against Speech Emotion Recognition Models
- Adversarial Exposure Attack on Diabetic Retinopathy Imagery Grading
- Relationship between manifold smoothness and adversarial vulnerability in deep learning with local errors
- Protecting Classifiers From Attacks
- Spatial-Frequency Discriminability for Revealing Adversarial Perturbations
- Improving Robustness of Jet Tagging Algorithms with Adversarial Training
- Artificial Immune System of Secure Face Recognition Against Adversarial Attacks
- The Intriguing Relation Between Counterfactual Explanations and Adversarial Examples
- The Thousand Faces of Explainable AI Along the Machine Learning Life Cycle: Industrial Reality and Current State of Research
- Adversarial Image Generation by Spatial Transformation in Perceptual Colorspaces
- Are Transformers More Robust? Towards Exact Robustness Verification for Transformers
- DiffDefense: Defending against Adversarial Attacks via Diffusion Models
- Dealing with Adversarial Player Strategies in the Neural Network Game iNNk through Ensemble Learning
- AccelAT: A Framework for Accelerating the Adversarial Training of Deep Neural Networks through Accuracy Gradient
- mFI-PSO: A Flexible and Effective Method in Adversarial Image Generation for Deep Neural Networks
- Accurate Real-time Polyp Detection in Videos from Concatenation of Latent Features Extracted from Consecutive Frames
- Tailoring Adversarial Attacks on Deep Neural Networks for Targeted Class Manipulation Using DeepFool Algorithm
- Robust Classification using Hidden Markov Models and Mixtures of Normalizing Flows
- Evaluating Similitude and Robustness of Deep Image Denoising Models via Adversarial Attack
- Towards a Kernel based Uncertainty Decomposition Framework for Data and Models
- IAE: Irony-based Adversarial Examples for Sentiment Analysis Systems
- Black-box Attacks on Image Activity Prediction and its Natural Language Explanations
- AICAttack: Adversarial Image Captioning Attack with Attention-Based Optimization
- Can Perceptual Guidance Lead to Semantically Explainable Adversarial Perturbations?
- Adversarial Attacks on Machine Learning-Aided Visualizations
- Generalization Error Analysis of Neural networks with Gradient Based Regularization
- Physics-constrained Attack against Convolution-based Human Motion Prediction
- Image Protection against Forgery and Pixel Tampering based on a Triple Hybrid Security Approach
- Cluster optical depth and pairwise velocity estimation using machine learning
- Scope and Sense of Explainability for AI-Systems
- Inconspicuous Adversarial Patches for Fooling Image Recognition Systems on Mobile Devices
- Adversarial Robustness on Image Classification with -means
- Efficient Reachability Analysis for Convolutional Neural Networks Using Hybrid Zonotopes
- Skeletonization-Based Adversarial Perturbations on Large Vision Language Model's Mathematical Text Recognition
- A Survey of Passive Sensing for Workplace Wellbeing and Productivity
- Imitation Game for Adversarial Disillusion with Chain-of-Thought Reasoning in Generative AI
- Chromatic and spatial analysis of one-pixel attacks against an image classifier