Evolution Attack On Neural Networks

06/21/2019
by   YiGui Luo, et al.
0

Many studies have been done to prove the vulnerability of neural networks to adversarial example. A trained and well-behaved model can be fooled by a visually imperceptible perturbation, i.e., an originally correctly classified image could be misclassified after a slight perturbation. In this paper, we propose a black-box strategy to attack such networks using an evolution algorithm. First, we formalize the generation of an adversarial example into the optimization problem of perturbations that represent the noise added to an original image at each pixel. To solve this optimization problem in a black-box way, we find that an evolution algorithm perfectly meets our requirement since it can work without any gradient information. Therefore, we test various evolution algorithms, including a simple genetic algorithm, a parameter-exploring policy gradient, an OpenAI evolution strategy, and a covariance matrix adaptive evolution strategy. Experimental results show that a covariance matrix adaptive evolution Strategy performs best in this optimization problem. Additionally, we also perform several experiments to explore the effect of different regularizations on improving the quality of an adversarial example.

READ FULL TEXT
research
11/28/2014

Two Gaussian Approaches to Black-Box Optomization

Outline of several strategies for using Gaussian processes as surrogate ...
research
05/18/2017

Limited-Memory Matrix Adaptation for Large Scale Black-box Optimization

The Covariance Matrix Adaptation Evolution Strategy (CMA-ES) is a popula...
research
10/17/2016

Evolving the Structure of Evolution Strategies

Various variants of the well known Covariance Matrix Adaptation Evolutio...
research
09/19/2023

Transferable Adversarial Attack on Image Tampering Localization

It is significant to evaluate the security of existing digital image tam...
research
04/30/2022

Optimizing One-pixel Black-box Adversarial Attacks

The output of Deep Neural Networks (DNN) can be altered by a small pertu...
research
09/21/2016

Using CMA-ES for tuning coupled PID controllers within models of combustion engines

Proportional integral derivative (PID) controllers are important and wid...
research
03/16/2019

On-line Search History-assisted Restart Strategy for Covariance Matrix Adaptation Evolution Strategy

Restart strategy helps the covariance matrix adaptation evolution strate...

Please sign up or login with your details

Forgot password? Click here to reset