Thundernna: a white box adversarial attack

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Ye, Linfeng, Hamidi, Shayan Mohajer
Format: Preprint
Published: 2021
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866916098393243648
author Ye, Linfeng
Hamidi, Shayan Mohajer
author_facet Ye, Linfeng
Hamidi, Shayan Mohajer
contents The existing work shows that the neural network trained by naive gradient-based optimization method is prone to adversarial attacks, adds small malicious on the ordinary input is enough to make the neural network wrong. At the same time, the attack against a neural network is the key to improving its robustness. The training against adversarial examples can make neural networks resist some kinds of adversarial attacks. At the same time, the adversarial attack against a neural network can also reveal some characteristics of the neural network, a complex high-dimensional non-linear function, as discussed in previous work. In This project, we develop a first-order method to attack the neural network. Compare with other first-order attacks, our method has a much higher success rate. Furthermore, it is much faster than second-order attacks and multi-steps first-order attacks.
format Preprint
id arxiv_https___arxiv_org_abs_2111_12305
institution arXiv
publishDate 2021
record_format arxiv
spellingShingle Thundernna: a white box adversarial attack
Ye, Linfeng
Hamidi, Shayan Mohajer
Machine Learning
92B20
I.2.m
The existing work shows that the neural network trained by naive gradient-based optimization method is prone to adversarial attacks, adds small malicious on the ordinary input is enough to make the neural network wrong. At the same time, the attack against a neural network is the key to improving its robustness. The training against adversarial examples can make neural networks resist some kinds of adversarial attacks. At the same time, the adversarial attack against a neural network can also reveal some characteristics of the neural network, a complex high-dimensional non-linear function, as discussed in previous work. In This project, we develop a first-order method to attack the neural network. Compare with other first-order attacks, our method has a much higher success rate. Furthermore, it is much faster than second-order attacks and multi-steps first-order attacks.
title Thundernna: a white box adversarial attack
topic Machine Learning
92B20
I.2.m
url https://arxiv.org/abs/2111.12305