A transfer-based adversarial attack method
Lü Li, Fengming Zhu, Zichen Yang · 2024
Deep convolutional neural network models are vulnerable to adversarial attacks, which can lead to incorrect classification by the model. This adversarial attack has become one of the challenges facing the full-scale deployment of artificial intelligence. Examining adversarial attacks, especially in image recognition, is beneficial. It not only uncovers the weaknesses of deep convolutional neural networks but also enhances our understanding of the security threats associated with deep neural networks, thereby facilitating their enhancement. Through an indepth analysis of the principles behind adversarial attacks, this paper proposes an adversarial attack algorithm aimed at target recognition models.One of the key challenges with current adversarial attack methodologies is their limited ability to produce adversarial examples that can be consistently effective across different models. The generation of such universally effective adversarial samples is a significant hurdle. Nonetheless, achieving this transferability is essential for assessing and bolstering the resilience of AI models against potential security threats. Therefore,this paper introduces a novel adversarial attack algorithm called AdvGAN-G Attack, building on the research surrounding adversarial attack methods that utilize Adversarial Generative Networks (AdvGAN). By utilizing the AdvGAN adversarial training principle and combining the conversion of sample space domain and frequency domain, the gradient editing mechanism is used to optimize the generator gradient parameters in the AdvGAN model, thereby generating adversarial samples with high transferability. Finally, by comparing the performance of AdvGAN-G Attack with other adversarial attack algorithms with transferability, the advantages of AdvGAN-G Attack in terms of sample transferability and algorithm runtime cost were verified, providing an effective solution for improving model robustness and addressing adversarial attack challenges.