Adaptive iterative attack towards explainable adversarial robustness

作者:

Highlights:

• We demonstrate the relationship between step size and iterative attack effect.

• We design the first iterative attack adaptively allocates step size.

• We achieve high attack effect with various models with two different norms.

• We visualize attack trajectories to show the motivation of adjustment on stepsize.

摘要

•We demonstrate the relationship between step size and iterative attack effect.•We design the first iterative attack adaptively allocates step size.•We achieve high attack effect with various models with two different norms.•We visualize attack trajectories to show the motivation of adjustment on stepsize.

论文关键词:Adversarial example,Adversarial attack,Image classification

论文评审过程:Received 28 June 2019, Revised 18 February 2020, Accepted 24 February 2020, Available online 27 February 2020, Version of Record 5 June 2020.

论文官网地址:https://doi.org/10.1016/j.patcog.2020.107309