Generating Adversarial Examples in One Shot With Image-to-Image Translation GAN
Weijia Zhang · IEEE Access · 2019
Deep Neural Networks (DNNs) provide state-of-the-art results for most machine learning and computer vision tasks. However, they have been found susceptible to adversarial examples. In the recent literature, many ways of generating adversarial examples have been discovered. In this work, we propose a novel method to generate adversarial examples with generative adversarial networks (GANs). Compared to traditional optimisation-based methods, our method provides a fast yet powerful alternative for adversary generation. Unlike other GAN-based approaches in the literature which learn to generate an intermediate perturbation vector, our method generates adversarial examples from benign input images in a straightforward manner. By directly generating adversarial examples from given input images, our method produces perturbations that better align with the underlying edge and shape contained in the inputs, hence more natural-looking and imperceptible to human eyes. We evaluate our method on the MNIST and the CIFAR-10 dataset and demonstrate that it outperforms the state-of-the-art GAN-based attack AdvGAN with similar attack capability in terms of distortion. We show that our method produces competitive results to notable optimisation-based attacks in the literature including the strongest Carlini & Wagner (CW) attack.