Generate Adversarial Examples by Nesterov-momentum Iterative Fast Gradient Sign Method
Jin Xue Xu · 2020
At present, the security of neural networks has attracted more and more attention, and the emergence of adversarial examples is one of the problems. The gradient-based attack algorithm is a representative attack algorithm. Among the gradient attack algorithms, the momentum iterative fast gradient sign method (MI-FGSM) is currently an efficient and typical attack algorithm. However, this method will cause the gradient to advance too fast and accelerate too much. In this article, we propose an attack algorithm based on Nesterov-momentum called Nesterov-momentum iterative fast gradient sign method (NMI-FGSM). Nesterov-momentum makes a correction when the gradient is updated to avoid moving too fast. Experiments show that our algorithm performs well and has achieved a high success rate. At the same time, under the same attack success rate, the perturbation value of the adversarial examples generated by our algorithm is smaller.