Adversarial Attacks with Minimal Perturbations

Hai‐Jun Su, Mengyuan Zhu, Mengqi Liu, Yunwei Zhang, Qian Zhang, Zekun Yang · 2024

Adversarial training generates adversarial samples by adding disturbances to the training data, simulating fraud or real-world attacks, thereby enhancing the neural network's resistance to such attacks. Traditional adversarial sample generation methods focus on achieving high success rates through global attacks without considering the disturbance region. Based on the analysis of adversarial sample gradients, we propose a Truncated Fast Gradient Sign Method (TFGSM). TFGSM is a local attack method that concentrates disturbances on regions with significant gradients, minimizing disruptions to the original sample. Extensive experiments demonstrate that our approach preserves the integrity of the original sample as much as possible without significantly reducing the attack success rate.

Read the paper · More papers on PaperTik