TY - GEN
T1 - Study on the Method of Adversarial Example Attack Based on MI-FGSM
AU - Mao, Guanqiao
AU - Li, Lu
AU - Wang, Qingyu
AU - Li, Junbao
N1 - Publisher Copyright:
© 2022, The Author(s), under exclusive license to Springer Nature Singapore Pte Ltd.
PY - 2022
Y1 - 2022
N2 - Deep neural network outperformed human beings in many fields such as image classification [1–3], object detection [4, 5], and image semantic segmentation [6] in recent years. But this model has security risks; for instance, it can be considered as a black box and can hardly change to improve its performance when the training is complete, nobody is able to explain the exact meaning of the weights of a model. Those fatal flaws above produce a real problem, deep neural network is vulnerable and will be attacked by adversarial examples [7–9]. In this paper, we use MI-FGSM algorithm on three typical convolution neural network and produce three sets of adversarial example. Then we use these three sets of adversarial examples to attack three typical convolutional neural networks mentioned above, called white box attack. Next, we train three new convolutional neural network and attack them, called black box attack. The attack described above at military target dataset has a significant effect.
AB - Deep neural network outperformed human beings in many fields such as image classification [1–3], object detection [4, 5], and image semantic segmentation [6] in recent years. But this model has security risks; for instance, it can be considered as a black box and can hardly change to improve its performance when the training is complete, nobody is able to explain the exact meaning of the weights of a model. Those fatal flaws above produce a real problem, deep neural network is vulnerable and will be attacked by adversarial examples [7–9]. In this paper, we use MI-FGSM algorithm on three typical convolution neural network and produce three sets of adversarial example. Then we use these three sets of adversarial examples to attack three typical convolutional neural networks mentioned above, called white box attack. Next, we train three new convolutional neural network and attack them, called black box attack. The attack described above at military target dataset has a significant effect.
KW - Adversarial example attack
KW - Convolutional neural network
KW - Military targets
KW - Misclassification
UR - https://www.scopus.com/pages/publications/85135099428
U2 - 10.1007/978-981-19-1057-9_27
DO - 10.1007/978-981-19-1057-9_27
M3 - 会议稿件
AN - SCOPUS:85135099428
SN - 9789811910562
T3 - Smart Innovation, Systems and Technologies
SP - 281
EP - 288
BT - Advances in Intelligent Information Hiding and Multimedia Signal Processing - Proceeding of the IIH-MSP 2021 and FITAT 2021
A2 - Chu, Shu-Chuan
A2 - Chen, Shi-Huang
A2 - Meng, Zhenyu
A2 - Ryu, Keun Ho
A2 - Tsihrintzis, George A.
PB - Springer Science and Business Media Deutschland GmbH
T2 - 17th International Conference on Intelligent Information Hiding and Multimedia Signal Processing, IIH-MSP 2021, in conjunction with the 14th International Conference on Frontiers of Information Technology, Applications and Tools, FITAT 2021
Y2 - 29 October 2021 through 31 October 2021
ER -