Euclidean and Rapid Jacobian-based Saliency Maps Attacks
Yue Ling, Zhang Yong, Wei Pengfei · 2021 16th International Conference on Intelligent Systems and Knowledge Engineering (ISKE) · 2021
Machine learning models is widely used in a variety of situations, such as autonomous driving, speech recognition and malware detection. Recent research shows that “adversarial examples” can fool Deep learning classifiers. Research on the security of machine learning models has also attracted extensive attention. The study of adversarial examples is of great significance to the improvement of model robustness. In particular, the Jacobian-based Saliency Map Attack(JSMA) is an attack based on L0distance, only change two pixels per iteration. In this paper, we mainly introduce Euclidean Jacobian-based Saliency Maps Attack(EJSMA) and Rapid Jacobian-based Saliency Maps Attacks(RJSMA). These attacks are improved on the basis of the JSMA, faster and more efficient version of JSMA. EJSMA uses the Grad-CAM method to construct a new saliency map, RJSMA aims to reduce the size of the Jacobian matrix and increase the speed of attack. To demonstrate the efficacy of these attacks, our experiment is carried out around two Deep Neural Network(DNN). EJSMA and RJSMA applications on 1) LeNet-5, a gradient-based backpropagation algorithm is used for supervised training of the network, on the MNIST [2] database, and on 2) a more complex NNC on the CIFAR-10 [3]. For instance, on LeNet-5, EJSMA exceed 98.93% in success rate for a maximum authorized distortion of 14.5%,compared with JSMA, 11 pp have been added. RJSMA greatly improves upon the speed of TJSMA, RJSMA are 3 times faster than TJSMA and 3.42 times faster than JSMA on MNIST. The new attacks can also be used to defend models and Improve the robustness of the model.