Black-box Evolutionary Search for Adversarial Examples against Deep Image Classifiers in Non-Targeted Attacks

Štěpán Procházka, Roman Neruda · 2020

Machine learning models exhibit vulnerability to adversarial examples i.e., artificially created inputs that become misinterpreted. The goal of this paper is to explore non-targeted black-box adversarial attacks on deep networks performing image classification. The original evolutionary algorithm for generating adversarial examples is proposed that employs a guided multi-objective search through the space of perturbed images. The efficiency of attacks is validated by experiments with the CIFAR-10 data set. The experimental results verify the usability of our approach against deep convolutional neural networks.

Read the paper · More papers on PaperTik