Generating Adversarial Examples with Image-To-Perturbation Network

Desheng Wang, Weidong Jin, Yunpu Wu · 2020

Deep neural networks have been found to be easily misled by adversarial examples that are maliciously crafted by adding small perturbations. A variety of methods have been proposed to generate adversarial examples, but more efforts are needed to generate them with high perceptual quality and low computation costs. In this paper, we propose an adversarial attack method that uses a conditional encoder-decoder network named Image-To-Perturbation to generate adversarial perturbations in residual learning fashion. Image-To-Perturbation network can learn the mapping from clean images to according adversarial perturbations, once it is trained, it can generate perturbations for any examples efficiently. We test the proposed method on different target models using MNIST and CIFAR-10 datasets. The experimental results show that our model is easy to train and the generated adversarial examples are perceptually realistic and achieve high attack success rate.

Read the paper · More papers on PaperTik