Principal Component Adversarial Example

被引:37
|
作者
Zhang, Yonggang [1 ]
Tian, Xinmei [1 ]
Li, Ya [1 ]
Wang, Xinchao [2 ]
Tao, Dacheng [3 ,4 ]
机构
[1] Univ Sci & Technol China, Dept Elect Engn & Informat Sci, Hefei 230027, Peoples R China
[2] Stevens Inst Technol, Dept Comp Sci, Hoboken, NJ 07030 USA
[3] Univ Sydney, UBTECH Sydney Artificial Intelligence Ctr, Sydney, NSW 2008, Australia
[4] Univ Sydney, Sch Comp Sci, Fac Engn, Sydney, NSW 2008, Australia
关键词
Manifolds; Neural networks; Perturbation methods; Distortion; Task analysis; Robustness; Principal component analysis; Deep learning; adversarial examples; classification; manifold learning; NEURAL-NETWORKS; DEEP; REPRESENTATION; ROBUSTNESS;
D O I
10.1109/TIP.2020.2975918
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Despite having achieved excellent performance on various tasks, deep neural networks have been shown to be susceptible to adversarial examples, i.e., visual inputs crafted with structural imperceptible noise. To explain this phenomenon, previous works implicate the weak capability of the classification models and the difficulty of the classification tasks. These explanations appear to account for some of the empirical observations but lack deep insight into the intrinsic nature of adversarial examples, such as the generation method and transferability. Furthermore, previous works generate adversarial examples completely rely on a specific classifier (model). Consequently, the attack ability of adversarial examples is strongly dependent on the specific classifier. More importantly, adversarial examples cannot be generated without a trained classifier. In this paper, we raise a question: what is the real cause of the generation of adversarial examples? To answer this question, we propose a new concept, called the adversarial region, which explains the existence of adversarial examples as perturbations perpendicular to the tangent plane of the data manifold. This view yields a clear explanation of the transfer property across different models of adversarial examples. Moreover, with the notion of the adversarial region, we propose a novel target-free method to generate adversarial examples via principal component analysis. We verify our adversarial region hypothesis on a synthetic dataset and demonstrate through extensive experiments on real datasets that the adversarial examples generated by our method have competitive or even strong transferability compared with model-dependent adversarial example generating methods. Moreover, our experiment shows that the proposed method is more robust to defensive methods than previous methods.
引用
收藏
页码:4804 / 4815
页数:12
相关论文
共 50 条
  • [1] Adversarial Principal Component Analysis
    Pimentel-Alarcon, Daniel L.
    Biswas, Aritra
    Solis-Lemus, Claudia R.
    2017 IEEE INTERNATIONAL SYMPOSIUM ON INFORMATION THEORY (ISIT), 2017, : 2363 - 2367
  • [2] ON THE ADVERSARIAL ROBUSTNESS OF PRINCIPAL COMPONENT ANALYSIS
    Li, Ying
    Li, Fuwei
    Lai, Lifeng
    Wu, Jun
    2021 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH AND SIGNAL PROCESSING (ICASSP 2021), 2021, : 3695 - 3699
  • [3] An example of principal component analysis applied to correlated images
    Maciejewski, AA
    Roberts, RG
    PROCEEDINGS OF THE 33RD SOUTHEASTERN SYMPOSIUM ON SYSTEM THEORY, 2001, : 269 - 273
  • [4] AED-PADA: Improving Generalizability of Adversarial Example Detection via Principal Adversarial Domain Adaptation
    Peng, Heqi
    Wang, Yunhong
    Yang, Ruijie
    Li, Beichen
    Wang, Rui
    Guo, Yuanfang
    ACM TRANSACTIONS ON MULTIMEDIA COMPUTING COMMUNICATIONS AND APPLICATIONS, 2025, 21 (02)
  • [5] An example of principal component analysis application on climate change assessment
    Tadic, Lidija
    Bonacci, Ognjen
    Brlekovic, Tamara
    THEORETICAL AND APPLIED CLIMATOLOGY, 2019, 138 (1-2) : 1049 - 1062
  • [6] An example of principal component analysis application on climate change assessment
    Lidija Tadić
    Ognjen Bonacci
    Tamara Brleković
    Theoretical and Applied Climatology, 2019, 138 : 1049 - 1062
  • [7] PERIODIC CLASSIFICATION: A DIDACTIC EXAMPLE TO TEACH PRINCIPAL COMPONENT ANALYSIS
    Lyra, Wellington da Silva
    da Silva, Edvan Cirino
    Ugulino de Araujo, Mario Cesar
    Fragoso, Wallace Duarte
    Veras, Germano
    QUIMICA NOVA, 2010, 33 (07): : 1594 - U380
  • [8] Image classification based on principal component analysis optimized generative adversarial networks
    Chunzhi Wang
    Pan Wu
    Lingyu Yan
    Zhiwei Ye
    Hongwei Chen
    Hefei Ling
    Multimedia Tools and Applications, 2021, 80 : 9687 - 9701
  • [9] Image classification based on principal component analysis optimized generative adversarial networks
    Wang, Chunzhi
    Wu, Pan
    Yan, Lingyu
    Ye, Zhiwei
    Chen, Hongwei
    Ling, Hefei
    MULTIMEDIA TOOLS AND APPLICATIONS, 2021, 80 (06) : 9687 - 9701
  • [10] Principal Component Regression by Principal Component Selection
    Lee, Hosung
    Park, Yun Mi
    Lee, Seokho
    COMMUNICATIONS FOR STATISTICAL APPLICATIONS AND METHODS, 2015, 22 (02) : 173 - 180