Stochastic sparse adversarial attacks
Manon Césaire, Lucas Schott, Hatem Hajri, Sylvain Lamprier, Patrick Gallinari · 2021 IEEE 33rd International Conference on Tools with Artificial Intelligence (ICTAI) · 2021
This paper introduces stochastic sparse adversarial attacks (SSAA), standing as simple, fast and purely noise-based targeted and untargeted attacks of neural network classifiers (NNC). SSAA offer new examples of sparse (or L0) attacks for which only few methods have been proposed previously. These attacks are devised by exploiting a small-time expansion idea widely used for Markov processes. Experiments on small and large datasets (CIFAR-10 and ImageNet) illustrate several advantages of SSAA in comparison with the-state-of-the-art methods. For instance, in the untargeted case, our method called Voting Folded Gaussian Attack (VFGA) scales efficiently to ImageNet and achieves a significantly lower L0score than SparseFool (up to $\frac{2}{5}$) while being faster. Moreover, VFGA achieves better L0scores on ImageNet than Sparse-RS when both attacks are fully successful on a large number of samples.