Related Experiment Videos
ATR-UAP: Enhancing the Transferability of Data-Free Universal Adversarial Perturbation via Adaptive Truncated Ratio
Summary
This study introduces ATR-UAP, a novel data-free method for creating universal adversarial perturbations (UAPs) that improve model robustness evaluation. ATR-UAP enhances transferability to unseen models without needing real training data.
Area of Science:
- Computer Vision
- Machine Learning Security
- Deep Learning Robustness
Background:
- Universal adversarial attacks generate image-agnostic perturbations (UAPs) for CNN robustness evaluation.
- Existing universal attack methods often require large datasets, which are impractical in real-world scenarios.
- Current data-free universal attack methods lack adaptive layer selection, limiting their transferability to new models.
Purpose of the Study:
- To propose a novel data-free universal attack method, ATR-UAP, that overcomes the limitations of existing approaches.
- To enhance the transferability and generalization of data-free universal adversarial perturbations (UAPs).
- To improve the efficiency and effectiveness of robustness evaluation for CNN models.
Main Methods:
- Developed an Adaptive Truncated Ratio Maximization (ATR-UAP) approach for data-free UAP generation.
- Integrated adaptive layer-wise weight learning with exclusive sparsity and prior guidance.
- Introduced a variance reduction strategy to stabilize CNN activation values during training.
- Proposed a curriculum-guided alternating optimization algorithm to promote input diversity and address optimization challenges.
Main Results:
- ATR-UAP demonstrated superior performance compared to state-of-the-art data-free UAP methods across various datasets.
- The proposed method showed significantly improved cross-model and cross-task transferability.
- Evaluations confirmed enhanced generalization and robustness of the generated data-free UAPs.
- Effectively addressed the limitations of rigid layer selection in prior data-free methods.
Conclusions:
- ATR-UAP offers an effective solution for generating data-free universal adversarial perturbations (UAPs).
- The method significantly improves the transferability and robustness of adversarial attacks.
- ATR-UAP provides a valuable tool for evaluating and enhancing the security of CNN models in data-constrained environments.