Adagard Accelerated Gradient with Weight Decay for Adversarial Attacks

Jiajun Tang, Zhong Wang, Qingdong Wei · 2022

Subtle noise added to the original images can affect the deep neural network model's accuracy, that is, the adversarial examples. Many tests have shown that adversarial examples have achieved a high success rate for many models, but their transferability needs to be improved for the models with adversarial training. Therefore, an adagard accelerated gradient with weight decay method is proposed to generate adversarial examples in this paper. To be more specific, in the iterative calculation of gradient, it is different from the momentum method to directly calculate the current gradient, we use adagard to calculate the gradient and use weight decay method to limit the weight, make the whole model weights are closer to zero, improve the generalization of models. The proposed method AWDI-FGSM could be more efficient in enhancing the transferability between different models, according to experiments on the ImageNet dataset.

Read the paper · More papers on PaperTik