A New Type of Adversarial Examples

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Nie, Xingyang, Xiao, Guojie, Pan, Su, Wang, Biao, Ge, Huilin, Fang, Tao
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909863610679296
author Nie, Xingyang
Xiao, Guojie
Pan, Su
Wang, Biao
Ge, Huilin
Fang, Tao
author_facet Nie, Xingyang
Xiao, Guojie
Pan, Su
Wang, Biao
Ge, Huilin
Fang, Tao
contents Most machine learning models are vulnerable to adversarial examples, which poses security concerns on these models. Adversarial examples are crafted by applying subtle but intentionally worst-case modifications to examples from the dataset, leading the model to output a different answer from the original example. In this paper, adversarial examples are formed in an exactly opposite manner, which are significantly different from the original examples but result in the same answer. We propose a novel set of algorithms to produce such adversarial examples, including the negative iterative fast gradient sign method (NI-FGSM) and the negative iterative fast gradient method (NI-FGM), along with their momentum variants: the negative momentum iterative fast gradient sign method (NMI-FGSM) and the negative momentum iterative fast gradient method (NMI-FGM). Adversarial examples constructed by these methods could be used to perform an attack on machine learning systems in certain occasions. Moreover, our results show that the adversarial examples are not merely distributed in the neighbourhood of the examples from the dataset; instead, they are distributed extensively in the sample space.
format Preprint
id arxiv_https___arxiv_org_abs_2510_19347
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle A New Type of Adversarial Examples
Nie, Xingyang
Xiao, Guojie
Pan, Su
Wang, Biao
Ge, Huilin
Fang, Tao
Machine Learning
Artificial Intelligence
Graphics
Most machine learning models are vulnerable to adversarial examples, which poses security concerns on these models. Adversarial examples are crafted by applying subtle but intentionally worst-case modifications to examples from the dataset, leading the model to output a different answer from the original example. In this paper, adversarial examples are formed in an exactly opposite manner, which are significantly different from the original examples but result in the same answer. We propose a novel set of algorithms to produce such adversarial examples, including the negative iterative fast gradient sign method (NI-FGSM) and the negative iterative fast gradient method (NI-FGM), along with their momentum variants: the negative momentum iterative fast gradient sign method (NMI-FGSM) and the negative momentum iterative fast gradient method (NMI-FGM). Adversarial examples constructed by these methods could be used to perform an attack on machine learning systems in certain occasions. Moreover, our results show that the adversarial examples are not merely distributed in the neighbourhood of the examples from the dataset; instead, they are distributed extensively in the sample space.
title A New Type of Adversarial Examples
topic Machine Learning
Artificial Intelligence
Graphics
url https://arxiv.org/abs/2510.19347