This website requires JavaScript.

Towards Transferable Unrestricted Adversarial Examples with Minimum Changes

Fangcheng LiuChao ZhangHongyang Zhang
摘要
Transfer-based adversarial example is one of the most important classes ofblack-box attacks. However, there is a trade-off between transferability andimperceptibility of the adversarial perturbation. Prior work in this directionoften requires a fixed but large $\ell_p$-norm perturbation budget to reach agood transfer success rate, leading to perceptible adversarial perturbations.On the other hand, most of the current unrestricted adversarial attacks thataim to generate semantic-preserving perturbations suffer from weakertransferability to the target model. In this work, we propose a geometry-awareframework to generate transferable adversarial examples with minimum changes.Analogous to model selection in statistical machine learning, we leverage avalidation model to select the optimal perturbation budget for each image underboth the $\ell_{\infty}$-norm and unrestricted threat models. Extensiveexperiments verify the effectiveness of our framework on balancingimperceptibility and transferability of the crafted adversarial examples. Themethodology is the foundation of our entry to the CVPR'21 Security AIChallenger: Unrestricted Adversarial Attacks on ImageNet, in which we ranked1st place out of 1,559 teams and surpassed the runner-up submissions by 4.59%and 23.91% in terms of final score and average image quality level,respectively. Code is available at https://github.com/Equationliu/GA-Attack.
展开全部
图表提取

暂无人提供速读十问回答

论文十问由沈向洋博士提出,鼓励大家带着这十个问题去阅读论文,用有用的信息构建认知模型。写出自己的十问回答,还有机会在当前页面展示哦。

Q1论文试图解决什么问题?
Q2这是否是一个新的问题?
Q3这篇文章要验证一个什么科学假设?
0
被引用
笔记
问答