Effective black box adversarial attack with handcrafted kernels

03/24/2023
by   Petr Dvořáček, et al.
0

We propose a new, simple framework for crafting adversarial examples for black box attacks. The idea is to simulate the substitution model with a non-trainable model compounded of just one layer of handcrafted convolutional kernels and then train the generator neural network to maximize the distance of the outputs for the original and generated adversarial image. We show that fooling the prediction of the first layer causes the whole network to be fooled and decreases its accuracy on adversarial inputs. Moreover, we do not train the neural network to obtain the first convolutional layer kernels, but we create them using the technique of F-transform. Therefore, our method is very time and resource effective.

READ FULL TEXT

page 4

page 7

research
11/20/2018

Intermediate Level Adversarial Attack for Enhanced Transferability

Neural networks are vulnerable to adversarial examples, malicious inputs...
research
09/01/2020

Defending against substitute model black box adversarial attacks with the 01 loss

Substitute model black box attacks can create adversarial examples for a...
research
04/04/2019

White-to-Black: Efficient Distillation of Black-Box Adversarial Attacks

Adversarial examples are important for understanding the behavior of neu...
research
07/11/2020

ManiGen: A Manifold Aided Black-box Generator of Adversarial Examples

Machine learning models, especially neural network (NN) classifiers, hav...
research
07/26/2023

Learning to simulate partially known spatio-temporal dynamics with trainable difference operators

Recently, using neural networks to simulate spatio-temporal dynamics has...
research
10/18/2022

It's a long way! Layer-wise Relevance Propagation for Echo State Networks applied to Earth System Variability

Artificial neural networks (ANNs) are known to be powerful methods for m...
research
06/15/2021

Code Integrity Attestation for PLCs using Black Box Neural Network Predictions

Cyber-physical systems (CPSs) are widespread in critical domains, and si...

Please sign up or login with your details

Forgot password? Click here to reset