CASIA OpenIR  > 模式识别实验室
Revisiting ensemble adversarial attack
Ziwen He1,2; Wei Wang1; Jing Dong1; Tieniu Tan1
发表期刊Signal Processing: Image Communication
2022
卷号107页码:116747
摘要

Deep neural networks have shown vulnerability to adversarial attacks. Adversarial examples generated with
an ensemble of source models can effectively attack unseen target models, posing a security threat to practical
applications. In this paper, we investigate the manner of ensemble adversarial attacks from the viewpoint
of network gradients with respect to inputs. We observe that most ensemble adversarial attacks simply
average gradients of the source models, ignoring their different contributions in the ensemble. To remedy
this problem, we propose two novel ensemble strategies, the Magnitude-Agnostic Bagging Ensemble (MABE)
strategy and Gradient-Grouped Bagging And Stacking Ensemble (G 2 BASE) strategy. The former builds on a
bagging ensemble and leverages a gradient normalization module to rebalance the ensemble weights. The latter
divides diverse models into different groups according to the gradient magnitudes and combines an intragroup
bagging ensemble with an intergroup stacking ensemble. Experimental results show that the proposed methods
enhance the success rate in white-box attacks and further boost the transferability in black-box attacks.

收录类别SCI ; EI
语种英语
是否为代表性论文
七大方向——子方向分类多模态智能
国重实验室规划方向分类多模态协同认知
是否有论文关联数据集需要存交
文献类型期刊论文
条目标识符http://ir.ia.ac.cn/handle/173211/51542
专题模式识别实验室
通讯作者Wei Wang
作者单位1.Center for Research on Intelligent Perception and Computing, NLPR, CASIA, Beijing 100190, China
2.School of Artificial Intelligence, University of Chinese Academy of Science (CAS), Beijing 100190, China
第一作者单位模式识别国家重点实验室
通讯作者单位模式识别国家重点实验室
推荐引用方式
GB/T 7714
Ziwen He,Wei Wang,Jing Dong,et al. Revisiting ensemble adversarial attack[J]. Signal Processing: Image Communication,2022,107:116747.
APA Ziwen He,Wei Wang,Jing Dong,&Tieniu Tan.(2022).Revisiting ensemble adversarial attack.Signal Processing: Image Communication,107,116747.
MLA Ziwen He,et al."Revisiting ensemble adversarial attack".Signal Processing: Image Communication 107(2022):116747.
条目包含的文件 下载所有文件
文件名称/大小 文献类型 版本类型 开放类型 使用许可
Revisiting ensemble (1597KB)期刊论文作者接受稿开放获取CC BY-NC-SA浏览 下载
个性服务
推荐该条目
保存到收藏夹
查看访问统计
导出为Endnote文件
谷歌学术
谷歌学术中相似的文章
[Ziwen He]的文章
[Wei Wang]的文章
[Jing Dong]的文章
百度学术
百度学术中相似的文章
[Ziwen He]的文章
[Wei Wang]的文章
[Jing Dong]的文章
必应学术
必应学术中相似的文章
[Ziwen He]的文章
[Wei Wang]的文章
[Jing Dong]的文章
相关权益政策
暂无数据
收藏/分享
文件名: Revisiting ensemble adversarial attack.pdf
格式: Adobe PDF
所有评论 (0)
暂无评论
 

除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。