An Adversarial Attack Algorithm based on Edge-Sketched Feature from Latent Space
Yangjie Cao, Chenxi Zhu, Haobo Wang, Yan Zhuang · 2022 2nd International Conference on Consumer Electronics and Computer Engineering (ICCECE) · 2022
Adversarial examples are specially designed examples which mislead deep learning models but could be correctly classified by human. They are usually generated by multiple iterations on the input according to the aim of increasing the classification loss. However, such approaches show slow training speed and unstable transferability. In this paper, we propose a latent space feature based adversarial attack algorithm, named as LSFAA, to address these technical challenges. LSFAA uses an Adversarial Feature Extraction Network to extract from inputs' latent space and utilizes these maps as adversarial perturbations. Thus the iterations are conducted on the parameters of the extraction network instead of the input. Therefore, the trained network is able to be used as a generator and mass generate adversarial examples without consuming too much time. Furthermore, an edge-sketched perturbation additional method is proposed to achieve imperceptible visualization. Inspired by convolutional neural network's characteristic of extracting edge information for further identification, we add the generated perturbation only on the chosen edge area of the input. Such method reaches a balance between attack ability and imperceptible visualization. Experimental results demonstrate that LSFAA achieves an average attack success rate of 99.21 % on four commonly used deep learning models.