Adversarial Samples Generation Based on RMSProp

Yacong Yu, Lei Zhang, Liquan Chen, Zhongyuan Qin · 2021 IEEE 6th International Conference on Signal and Image Processing (ICSIP) · 2021

Adversarial sample attacks seriously threaten the security and robustness of deep learning models. There are three problems in state-of-the-art adversarial sample generation schemes: the gradient update step size needs to be manually selected, inaccurate gradient update direction and uncontrollable times of iterations. In order to solve these problems, Root Mean Square Prop optimization algorithm (RMSProp) is proposed, which is integrated with IFGSM and IFGM. This algorithm can be easily extended to other attacks, and to a certain extent it can alleviate the trade-off between white box attacks and deliverability. The algorithm proposed in this paper can generate non-targeted adversarial samples more efficiently and quickly. Experiments show that it can generate effective and robust adversarial samples against current mainstream convolutional neural network (CNN).

Read the paper · More papers on PaperTik