清晨好,您是今天最早来到科研通的研友!由于当前在线用户较少,发布求助请尽量完整地填写文献信息,科研通机器人24小时在线,伴您科研之路漫漫前行!

Improving Transferability of Adversarial Samples via Critical Region-Oriented Feature-Level Attack

计算机科学 对抗制 卷积神经网络 人工智能 可转让性 加权 标杆管理 特征(语言学) 模式识别(心理学) 机器学习 数据挖掘 放射科 哲学 罗伊特 业务 营销 医学 语言学
作者
LI Zhi-wei,Min Ren,Qi Li,Fangling Jiang,Zhenan Sun
出处
期刊:IEEE Transactions on Information Forensics and Security [Institute of Electrical and Electronics Engineers]
卷期号:19: 6650-6664
标识
DOI:10.1109/tifs.2024.3404857
摘要

Deep neural networks (DNNs) have received a lot of attention because of their impressive progress in computer vision. However, it has been recently shown that DNNs are vulnerable to being spoofed by carefully crafted adversarial samples. These samples are generated by specific attack algorithms that can obfuscate the target model without being detected by humans. Recently, feature-level attacks have been the focus of research due to their high transferability. Existing state-of-the-art feature-level attacks all improve the transferability by greedily changing the attention of the model. However, for images that contain multiple target class objects, the attention of different models may differ significantly. Thus greedily changing attention may cause the adversarial samples corresponding to these images to fall into the local optimum of the surrogate model. Furthermore, due to the great structural differences between vision transformers (ViTs) and convolutional neural networks (CNNs), adversarial samples generated on CNNs with feature-level attacks are more difficult to successfully attack ViTs. To overcome these drawbacks, we perform the Critical Region-oriented Feature-level Attack (CRFA) in this paper. Specifically, we first propose the Perturbation Attention-aware Weighting (PAW), which destroys critical regions of the image by performing feature-level attention weighting on the adversarial perturbations without changing the model attention as much as possible. Then we propose the Region ViT-critical Retrieval (RVR), which enables the generator to accommodate the transferability of adversarial samples on ViTs by adding extra prior knowledge of ViTs to the decoder. Extensive experiments demonstrate significant performance improvements achieved by our approach, i.e., improving the fooling rate by 19.9% against CNNs and 25.0% against ViTs as compared to state-of-the-art feature-level attack method.

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
26秒前
MOKATA发布了新的文献求助10
32秒前
话说dota完成签到 ,获得积分10
33秒前
乐乐完成签到,获得积分10
34秒前
SCINEXUS完成签到,获得积分0
46秒前
King完成签到 ,获得积分10
53秒前
王珏完成签到,获得积分10
1分钟前
我是老大应助MOKATA采纳,获得10
1分钟前
Alisha完成签到,获得积分10
1分钟前
67完成签到 ,获得积分10
1分钟前
龙弟弟完成签到 ,获得积分10
1分钟前
Kao应助科研通管家采纳,获得10
1分钟前
Kao应助科研通管家采纳,获得10
1分钟前
1分钟前
stone完成签到,获得积分10
2分钟前
1515完成签到,获得积分10
2分钟前
MOKATA发布了新的文献求助10
2分钟前
2分钟前
许俊梁完成签到,获得积分10
2分钟前
2分钟前
许俊梁发布了新的文献求助10
2分钟前
称心谷南发布了新的文献求助10
2分钟前
MOKATA完成签到,获得积分20
2分钟前
3分钟前
晴空万里完成签到 ,获得积分10
3分钟前
科研通AI6.4应助MOKATA采纳,获得10
3分钟前
Aeeeeeeon完成签到 ,获得积分10
3分钟前
changyouhuang完成签到,获得积分10
3分钟前
橙橙完成签到 ,获得积分10
3分钟前
dxp123应助pang采纳,获得10
3分钟前
YZY完成签到 ,获得积分10
3分钟前
不安的如天完成签到,获得积分10
3分钟前
Kao应助科研通管家采纳,获得10
3分钟前
默默问芙完成签到,获得积分10
4分钟前
4分钟前
apckkk完成签到 ,获得积分10
4分钟前
诸葛小哥哥完成签到 ,获得积分0
4分钟前
MOKATA发布了新的文献求助10
4分钟前
4分钟前
故事的角色应助ppat5012采纳,获得10
4分钟前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
Nondestructive Testing Handbook: Vol. 4, Thermal and Infrared Testing (IR), 4th ed 800
作者名:Kristopher P. Plain,悉尼大学的,目前只能查到其四篇论文,想找到其博士论文 590
Évora na Idade Média 555
Soil mites of the family Rhagidiidae (Actinedida: Eupodoidea). Morphology, Systematics, Ecology 520
Matrix Methods in Data Mining and Pattern Recognition Second Edition 510
Radical Reactions 500
热门求助领域 (近24小时)
化学 材料科学 医学 生物 纳米技术 工程类 有机化学 化学工程 生物化学 计算机科学 内科学 物理 复合材料 催化作用 细胞生物学 无机化学 光电子学 物理化学 电极 基因
热门帖子
关注 科研通微信公众号,转发送积分 7355228
求助须知:如何正确求助?哪些是违规求助? 8966118
关于积分的说明 19048450
捐赠科研通 7003103
什么是DOI,文献DOI怎么找? 3222075
关于科研通互助平台的介绍 2386331
邀请新用户注册赠送积分活动 2202691