跳到主要导航 跳到搜索 跳到主要内容

A Method for Robustness Testing of Intelligent Classification Models: Adversarial Sample Generation under Score-based Gray-box Single-pixel Attacks

  • Yeyang Liu
  • , Yangyang Sun
  • , Yiwei Wang
  • , Changjian Wu
  • , Changdi Zhao
  • , Feng Jiang
  • , Liang Ni
  • , Xiaobin Li
  • , Dezhen Yang*
  • *此作品的通讯作者
  • Beihang University
  • Beijing Institute of Control and Electronic Technology

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

Utilizing adversarial samples is essential for assessing the robustness of intelligent classification models. However, certain adversarial sample generation methods based on the grey-box approach face challenges, including low attack efficiency and limited interpretability. This paper presents the Score-based Gray-box Single-pixel Attacks (SGSA) method, a novel approach for generating adversarial samples. Initially, the feature map of the model's final layer is extracted, along with computing the discrepancy between the predicted score of each feature map and the original prediction score. By employing the Leaky ReLU activation function, the score of each pixel is computed. Subsequently, these scores are sorted in ascending order. Initiating the attack from the pixel with the lowest score, the most effective attack direction is determined by comparing the outcomes of both forward and reverse adversarial attacks on each pixel. The results demonstrate that this method not only achieves high attack efficiency but also offers interpretability in selecting attack locations, and the attack efficiency has doubled. Furthermore, this method offers valuable guidance for both testing and enhancing the model's robustness to some degree.

源语言英语
主期刊名Proceedings - 2024 15th International Conference on Reliability, Maintenance and Safety, ICRMS 2024
出版商Institute of Electrical and Electronics Engineers Inc.
1067-1073
页数7
ISBN(电子版)9798331529116
DOI
出版状态已出版 - 2024
活动15th International Conference on Reliability, Maintenance and Safety, ICRMS 2024 - Gulin, 中国
期限: 31 7月 20242 8月 2024

出版系列

姓名Proceedings - 2024 15th International Conference on Reliability, Maintenance and Safety, ICRMS 2024

会议

会议15th International Conference on Reliability, Maintenance and Safety, ICRMS 2024
国家/地区中国
Gulin
时期31/07/242/08/24

学术指纹

探究 'A Method for Robustness Testing of Intelligent Classification Models: Adversarial Sample Generation under Score-based Gray-box Single-pixel Attacks' 的科研主题。它们共同构成独一无二的学术指纹。

引用此