Saved in:
| Main Author: | |
|---|---|
| Format: | Artículo científico |
| Language: | en |
| Published: |
Universidad San Francisco de Quito
2025
|
| Subjects: | |
| Online Access: | https://www.redalyc.org/articulo.oa?id=726182980004 https://www.redalyc.org/journal/7261/726182980004/ https://www.redalyc.org/journal/7261/726182980004/html/ https://www.redalyc.org/journal/7261/726182980004/726182980004.epub https://www.redalyc.org/journal/7261/726182980004/movil https://doi.org/10.18272/aci.vi.3699 |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Table of Contents:
- PoI+NBU: A feasibility study in generating high-resolution adversarial images with a black box evolutional algorithm based attack Enea Mancellari Ali Osman Topal Franck Leprévost Multidisciplinaria (Ciencias Naturales y Exactas) Black Up method box attack Noise Blowing Pixels of Interest Adversarial attacks in the digital image domain pose significant challenges to the robustness of machine learning models. Trained convolutional neural networks (CNNs) are among the leading tools used for the automatic classification of images. They are nevertheless exposed to attacks: given an input clean image classified by a CNN in a category, carefully designed adversarial images may lead CNNs to erroneous classifications, although humans would still classify “correctly” the constructed adversarial images in the same category as the input image. In this feasibility study, we propose a novel approach to enhance adversarial attacks by incorporating a pixel of interest detection mechanism. Our method involves utilizing the BagNet model to identify the most relevant pixels, allowing the attack to focus exclusively on these pixels and thereby speeding up the process of adversarial attack generation. These attacks are executed in the low-resolution domain, and then the Noise Blowing-Up (NBU) strategy transforms the low-resolution adversarial images into high-resolution adversarial images. The PoI+NBU strategy is tested on an evolutionary-based black-box targeted attack against MobileNet trained on ImageNet using 100 clean images. We observed that this approach increased the speed of the attack by approximately 65%. 2025 artículo científico 1390-5384 https://www.redalyc.org/articulo.oa?id=726182980004 https://www.redalyc.org/journal/7261/726182980004/ https://www.redalyc.org/journal/7261/726182980004/html/ https://www.redalyc.org/journal/7261/726182980004/726182980004.epub https://www.redalyc.org/journal/7261/726182980004/movil https://doi.org/10.18272/aci.vi.3699 en http://www.redalyc.org/revista.oa?id=7261 Avances en Ciencias e Ingenierías application/pdf Universidad San Francisco de Quito Avances en Ciencias e Ingenierías (Ecuador) Num.2 Vol.17