Study of Optimiser-Based Enhancement of Adversarial Attacks on Neural Networks

R. Zhou · 2024

In an era where neural network robustness is paramount, our research investigates the role of optimization algorithms in enhancing the effectiveness of adversarial attacks. By integrating the Adam optimizer—renowned for its efficiency in neural network training—into the generation of adversarial examples, we propose the Adam Iterative Fast Gradient Method (AI-FGM). This method capitalizes on Adam's adaptive learning rates and momentum to fine-tune adversarial perturbations, facilitating a more precise exploitation of model vulnerabilities and improving the transferability of the attacks across different architectures. Our comprehensive experiments, conducted across seven diverse neural network models, both standard and adversarially trained, demonstrate that AI-FGM outperforms traditional attacks like Fast Gradient Sign Method (FGSM), Iterative Fast Gradient Sign Method (I-FGSM), and Momentum Iterative Fast Gradient Sign Method (MI-FGSM). The study reveals a significant decrease in model accuracy when subjected to AI-FGM, underscoring its potency. Furthermore, by adopting a fusion of logits approach, we extend the application of AI-FGM to ensemble networks, highlighting the method's scalability and effectiveness in targeting shared weaknesses within model clusters. This research underscores the potential of utilizing advanced optimization strategies in adversarial example generation and calls attention to the necessity for the development of more sophisticated neural network defense mechanisms to counteract such enhanced adversarial techniques.

Read the paper · More papers on PaperTik