Skip to main navigation Skip to search Skip to main content

Study on the Method of Adversarial Example Attack Based on MI-FGSM

  • Guanqiao Mao
  • , Lu Li
  • , Qingyu Wang
  • , Junbao Li*
  • *Corresponding author for this work
  • School of Electronics and Information Engineering, Harbin Institute of Technology
  • Defence Industry Secrecy Examination and Certification Center

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Deep neural network outperformed human beings in many fields such as image classification [1–3], object detection [4, 5], and image semantic segmentation [6] in recent years. But this model has security risks; for instance, it can be considered as a black box and can hardly change to improve its performance when the training is complete, nobody is able to explain the exact meaning of the weights of a model. Those fatal flaws above produce a real problem, deep neural network is vulnerable and will be attacked by adversarial examples [7–9]. In this paper, we use MI-FGSM algorithm on three typical convolution neural network and produce three sets of adversarial example. Then we use these three sets of adversarial examples to attack three typical convolutional neural networks mentioned above, called white box attack. Next, we train three new convolutional neural network and attack them, called black box attack. The attack described above at military target dataset has a significant effect.

Original languageEnglish
Title of host publicationAdvances in Intelligent Information Hiding and Multimedia Signal Processing - Proceeding of the IIH-MSP 2021 and FITAT 2021
EditorsShu-Chuan Chu, Shi-Huang Chen, Zhenyu Meng, Keun Ho Ryu, George A. Tsihrintzis
PublisherSpringer Science and Business Media Deutschland GmbH
Pages281-288
Number of pages8
ISBN (Print)9789811910562
DOIs
StatePublished - 2022
Externally publishedYes
Event17th International Conference on Intelligent Information Hiding and Multimedia Signal Processing, IIH-MSP 2021, in conjunction with the 14th International Conference on Frontiers of Information Technology, Applications and Tools, FITAT 2021 - Kaohsiung, Taiwan, Province of China
Duration: 29 Oct 202131 Oct 2021

Publication series

NameSmart Innovation, Systems and Technologies
Volume277
ISSN (Print)2190-3018
ISSN (Electronic)2190-3026

Conference

Conference17th International Conference on Intelligent Information Hiding and Multimedia Signal Processing, IIH-MSP 2021, in conjunction with the 14th International Conference on Frontiers of Information Technology, Applications and Tools, FITAT 2021
Country/TerritoryTaiwan, Province of China
CityKaohsiung
Period29/10/2131/10/21

Keywords

  • Adversarial example attack
  • Convolutional neural network
  • Military targets
  • Misclassification

Fingerprint

Dive into the research topics of 'Study on the Method of Adversarial Example Attack Based on MI-FGSM'. Together they form a unique fingerprint.

Cite this