Guided Adversarial Attack for Evaluating and Enhancing Adversarial Defenses

被引:0
|
作者
Sriramanan, Gaurang [1 ]
Addepalli, Sravanti [1 ]
Baburaj, Arya [1 ]
Babu, R. Venkatesh [1 ]
机构
[1] Indian Inst Sci, Dept Computat & Data Sci, Video Analyt Lab, Bangalore, India
关键词
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Advances in the development of adversarial attacks have been fundamental to the progress of adversarial defense research. Efficient and effective attacks are crucial for reliable evaluation of defenses, and also for developing robust models. Adversarial attacks are often generated by maximizing standard losses such as the cross-entropy loss or maximum-margin loss within a constraint set using Projected Gradient Descent (PGD). In this work, we introduce a relaxation term to the standard loss, that finds more suitable gradient-directions, increases attack efficacy and leads to more efficient adversarial training. We propose Guided Adversarial Margin Attack (GAMA), which utilizes function mapping of the clean image to guide the generation of adversaries, thereby resulting in stronger attacks. We evaluate our attack against multiple defenses and show improved performance when compared to existing attacks. Further, we propose Guided Adversarial Training (GAT), which achieves state-of-the-art performance amongst single-step defenses by utilizing the proposed relaxation term for both attack generation and training.
引用
收藏
页数:12
相关论文
共 50 条
  • [21] On Adaptive Attacks to Adversarial Example Defenses
    Tramer, Florian
    Carlini, Nicholas
    Brendel, Wieland
    Madry, Aleksander
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 33, NEURIPS 2020, 2020, 33
  • [22] Adversarial Attacks and Defenses in Deep Learning
    Ren, Kui
    Zheng, Tianhang
    Qin, Zhan
    Liu, Xue
    ENGINEERING, 2020, 6 (03) : 346 - 360
  • [23] Towards Universal Adversarial Examples and Defenses
    Rakin, Adnan Siraj
    Wang, Ye
    Aeron, Shuchin
    Koike-Akino, Toshiaki
    Moulin, Pierre
    Parsons, Kieran
    2021 IEEE INFORMATION THEORY WORKSHOP (ITW), 2021,
  • [24] Adversarial Trends in Mobile Communication Systems: From Attack Patterns to Potential Defenses Strategies
    Chen, Hsin Yi
    Rao, Siddharth Prakash
    SECURE IT SYSTEMS, NORDSEC 2021, 2021, 13115 : 153 - 171
  • [25] A Survey of Adversarial Defenses and Robustness in NLP
    Goyal, Shreya
    Doddapaneni, Sumanth
    Khapra, Mitesh M.
    Ravindran, Balaraman
    ACM COMPUTING SURVEYS, 2023, 55 (14S)
  • [26] Comparative Study of Adversarial Defenses: Adversarial Training and Regularization in Vision Transformers and CNNs
    Dingeto, Hiskias
    Kim, Juntae
    ELECTRONICS, 2024, 13 (13)
  • [27] Quantization Aware Attack: Enhancing Transferable Adversarial Attacks by Model Quantization
    Yang, Yulong
    Lin, Chenhao
    Li, Qian
    Zhao, Zhengyu
    Fan, Haoran
    Zhou, Dawei
    Wang, Nannan
    Liu, Tongliang
    Shen, Chao
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 3265 - 3278
  • [28] Enhancing Boundary Attack in Adversarial Image Using Square Random Constraint
    Tran Van Sang
    Tran Phuong Thao
    Yamaguchi, Rie Shigetomi
    Nakata, Toshiyuki
    PROCEEDINGS OF THE 2022 ACM INTERNATIONAL WORKSHOP ON SECURITY AND PRIVACY ANALYTICS (IWSPA '22), 2022, : 13 - 23
  • [29] Provable Defenses against Adversarial Examples via the Convex Outer Adversarial Polytope
    Wong, Eric
    Kolter, J. Zico
    INTERNATIONAL CONFERENCE ON MACHINE LEARNING, VOL 80, 2018, 80
  • [30] Iterative Adversarial Attack on Image-Guided Story Ending Generation
    Wang, Youze
    Hu, Wenbo
    Hong, Richang
    IEEE TRANSACTIONS ON MULTIMEDIA, 2024, 26 : 6117 - 6130