Fool ’Em All — Fool-X: A Powerful & Fast Method for Generating Effective Adversarial Images

Samer Y. Khamaiseh, Mathew Mancino, Deirdre Jost, Abdullah Al-Alaj, Derek Bagagem, Edoardo Serra · 2024

The well-trained image classification neural networks are vulnerable to adversarial examples. An adversarial example is a malicious input carefully crafted by adding small perturbations to the original input, leading to misclassification. Despite advancements in generating adversarial examples, to the best of our knowledge, none of the well-known adversarial attacks can generate effective adversarial examples that work efficiently on large-scale datasets and very deep neural network architectures. In contrast to ordinary adversarial examples, effective adversarial examples have all the following four characteristics: (1) the ability to maximize the loss of DNNs, (2) the ability to cause a high misclassification rate for both undefended and defended DNN models using various defense methods, (3) minimal perturbations with low computational overhead on large-scale datasets, (4) the ability to be transferable across different DNN architectures.To fill this void, we propose Fool-X, an algorithm to generate effective adversarial examples with the least perturbations that can fool state-of-the-art image classification neural networks. To evaluate the performance of Fool-X, we have conducted extensive experiments using 12 baseline adversarial training defense methods and six state-of-the-art adversarial attacks. The results reported on ImageNet-ILSVRC, CIFAR-100, and CIFAR-10 demonstrate that the proposed Fool-X algorithm can generate effective adversarial examples on large-scale datasets that can successfully fool the well-trained, defended image classification neural networks and significantly outperform the state-of-the-art adversarial attacks. The code is available: https://github.com/LAiSR-SK/fool-X-Attack

Read the paper · More papers on PaperTik