Skip to main navigation Skip to search Skip to main content

A multi-objective examples generation approach to fool the deep neural networks in the black-box scenario

  • Harbin Institute of Technology Shenzhen

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Image classifiers have been proven to be easily fooled by perturbations, but it is still exceedingly challenging to generate imperceptible disturbances, especially without the internal knowledge of the classifiers. Imperceptibility and attack capability are two main evaluating indicators of this problem, while most existing methods, so far, can only either maximize misclassification or minimize the distortion. Although there are some algorithms to consider both of them via the weighted sum method, which is equivalent to solve the multiple optimization problems, it will doubtless enlarge the computation complexity, and the strategy of setting the weights cannot make sure both indicators the optimal solutions. In this paper, we proposed an innovative general algorithm named MOEA-APGA, which is based on multi-objective evolutionary algorithm, taking both factors as the optimization objective function. A set of perturbations with diversity is generated by population evolution, and then an appropriate perturbation is selected by the proposed filtering strategy to synthesize the adversarial example. It can achieve the goal of the targeted attack without the internal knowledge of the victim networks. We tried four perturbation strategies to generate adversarial examples. The experimental results on the MNIST datasets demonstrate the effectiveness of MOEA-APGA. In addition, we refer to a slice of indicators to evaluate the power of the algorithm and the vulnerability of different samples.

Original languageEnglish
Title of host publicationProceedings - 2019 IEEE 4th International Conference on Data Science in Cyberspace, DSC 2019
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages92-99
Number of pages8
ISBN (Electronic)9781728145280
DOIs
StatePublished - Jun 2019
Externally publishedYes
Event4th IEEE International Conference on Data Science in Cyberspace, DSC 2019 - Hangzhou, China
Duration: 23 Jun 201925 Jun 2019

Publication series

NameProceedings - 2019 IEEE 4th International Conference on Data Science in Cyberspace, DSC 2019

Conference

Conference4th IEEE International Conference on Data Science in Cyberspace, DSC 2019
Country/TerritoryChina
CityHangzhou
Period23/06/1925/06/19

Keywords

  • Adversarial examples
  • Black box attack
  • Deep neural networks
  • Multi objective optimization

Fingerprint

Dive into the research topics of 'A multi-objective examples generation approach to fool the deep neural networks in the black-box scenario'. Together they form a unique fingerprint.

Cite this