mFI-PSO: A Flexible and Effective Method in Adversarial Image Generation for Deep Neural Networks
arXiv:2006.03243 · doi:10.1109/IJCNN55064.2022.9892433
Abstract
Deep neural networks (DNNs) have achieved great success in image classification, but can be very vulnerable to adversarial attacks with small perturbations to images. To improve adversarial image generation for DNNs, we develop a novel method, called mFI-PSO, which utilizes a Manifold-based First-order Influence measure for vulnerable image and pixel selection and the Particle Swarm Optimization for various objective functions. Our mFI-PSO can thus effectively design adversarial images with flexible, customized options on the number of perturbed pixels, the misclassification probability, and the targeted incorrect class. Experiments demonstrate the flexibility and effectiveness of our mFI-PSO in adversarial attacks and its appealing advantages over some popular methods.
Accepted by 2022 International Joint Conference on Neural Networks (IJCNN)
References in corpus (8)
- Explaining and Harnessing Adversarial Examples
- One pixel attack for fooling deep neural networks
- DeepID3: Face Recognition with Very Deep Neural Networks
- Sensitivity and Generalization in Neural Networks: an Empirical Study
- Perturbation selection and influence measures in local influence analysis
- Sensitivity Analysis of Deep Neural Networks
- A Two-Stage Cascade Model with Variational Autoencoders and Attention Gates for MRI Brain Tumor Segmentation
- Potential adversarial samples for white-box attacks