Related Experiment Videos
Improving the Transferability of Adversarial Examples With a Noise Data Enhancement Framework and Random Erasing
Pengfei Xie1, Shuhao Shi1, Shuai Yang1
1Henan Key Laboratory of Imaging and Intelligent Processing, PLA Strategy Support Force Information Engineering University, Zhengzhou, China.
Frontiers in Neurorobotics
|December 27, 2021
Summary
This study introduces a novel noise data enhancement framework (NDEF) to improve black-box adversarial attacks on deep neural networks. The new Random Erasing Iterative Fast Gradient Sign Method (REI-FGSM) significantly boosts attack success rates against various models.
Area of Science:
- Artificial Intelligence
- Machine Learning Security
- Deep Neural Networks
Background:
- Deep neural networks (DNNs) are vulnerable to adversarial examples, posing risks to AI applications.
- Black-box transfer attacks are a significant threat, especially when target models are inaccessible.
- Existing data enhancement methods for attacks often rely on accuracy or loss invariance, limiting their applicability.
Purpose of the Study:
- To propose a new noise data enhancement framework (NDEF) for black-box adversarial attacks.
- To address limitations of previous frameworks that fail with information-losing transformations.
- To enhance the effectiveness of adversarial attacks without requiring target model access.
Main Methods:
- Introduced a novel noise data enhancement framework (NDEF) focusing on adversarial perturbation.
- Integrated random erasing within the NDEF to mitigate adversarial example over-fitting.
- Developed and evaluated the Random Erasing Iterative Fast Gradient Sign Method (REI-FGSM).
- Demonstrated compatibility with other transformations like Gaussian blur.
Main Results:
- REI-FGSM achieved a 4.2% higher average black-box attack success rate than DI-FGSM across six models.
- REI-FGSM showed a 6.6% higher success rate than DI-FGSM against three defense models.
- Combining REI-FGSM with SI-FGSM improved attack performance by an average of 22.9%.
- A combined method, DI-TI-MI-REI-FGSM, achieved 97.0% average success rate against ensemble adversarial training models.
Conclusions:
- The proposed NDEF effectively enhances black-box adversarial attacks, overcoming limitations of prior methods.
- REI-FGSM demonstrates superior performance and compatibility with various transformations and attack strategies.
- The framework offers a promising direction for improving adversarial attack capabilities in black-box scenarios.
Related Concept Videos
Masking and Demasking Agents
2.7K
EDTA titrations may necessitate masking and demasking agents to temporarily protect a particular metal ion in a mixture from the EDTA reaction. These agents facilitate the sequential analysis of the metal ions by forming stable complexes with some—but not all—metal ions during certain steps.
There are many masking agents, such as cyanide, fluoride, triethanolamine, thiourea, and 2,3-bis(sulfanyl)propan-1-ol (formerly 2,3-dimercapto-1-propanol), with the masking agent chosen based on...
There are many masking agents, such as cyanide, fluoride, triethanolamine, thiourea, and 2,3-bis(sulfanyl)propan-1-ol (formerly 2,3-dimercapto-1-propanol), with the masking agent chosen based on...
2.7K
Random and Systematic Errors
13.2K
Scientists always try their best to record measurements with the utmost accuracy and precision. However, sometimes errors do occur. These errors can be random or systematic. Random errors are observed due to the inconsistency or fluctuation in the measurement process, or variations in the quantity itself that is being measured. Such errors fluctuate from being greater than or less than the true value in repeated measurements. Consider a scientist measuring the length of an earthworm using a...
13.2K
Randomized Experiments
8.1K
The randomization process involves assigning study participants randomly to experimental or control groups based on their probability of being equally assigned. Randomization is meant to eliminate selection bias and balance known and unknown confounding factors so that the control group is similar to the treatment group as much as possible. A computer program and a random number generator can be used to assign participants to groups in a way that minimizes bias.
Simple randomization
Simple...
Simple randomization
Simple...
8.1K
Propagation of Uncertainty from Random Error
1.2K
An experiment often consists of more than a single step. In this case, measurements at each step give rise to uncertainty. Because the measurements occur in successive steps, the uncertainty in one step necessarily contributes to that in the subsequent step. As we perform statistical analysis on these types of experiments, we must learn to account for the propagation of uncertainty from one step to the next. The propagation of uncertainty depends on the type of arithmetic operation performed on...
1.2K
Improving Translational Accuracy
12.0K
Base complementarity between the three base pairs of mRNA codon and the tRNA anticodon is not a failsafe mechanism. Inaccuracies can range from a single mismatch to no correct base pairing at all. The free energy difference between the correct and nearly correct base pairs can be as small as 3 kcal/ mol. With complementarity being the only proofreading step, the estimated error frequency would be one wrong amino acid in every 100 amino acids incorporated. However, error frequencies observed in...
12.0K
Generalization, Discrimination, and Extinction
875
Generalization, discrimination, and extinction are key concepts in operant conditioning that influence how behaviors are learned and maintained.
Generalization occurs when a behavior reinforced in one context is performed in similar situations. For instance, a student who studies diligently for calculus and receives excellent grades might apply the same study habits to psychology and history, expecting similar results. Generalization shows how learning in one setting can influence behavior in...
Generalization occurs when a behavior reinforced in one context is performed in similar situations. For instance, a student who studies diligently for calculus and receives excellent grades might apply the same study habits to psychology and history, expecting similar results. Generalization shows how learning in one setting can influence behavior in...
875