The Migration Analysis of Adversarial Examples with Convolutional Neural Networks

Authors

  • Jin Xing

DOI:

https://doi.org/10.61173/y44qkq41

Keywords:

Adversarial Examples, Neural Network, Convolutional Neural Networks, Deep Learning

Abstract

Recently, with the attention of researchers on the adversarial attack technology, the robustness of neural networks has become an urgent problem. An adversarial attack is a way to mislead the deep-learning neural networks and make several changes to the sample, which lets the model provide the wrong output with a high confidence level. Using these methods to attack some specific deep learning models achieves remarkable results, but the robustness of different neural network models has not yet been clarified. This paper studies the migration of adversarial examples, aiming to conclude whether the adversarial examples from specific models are also practical when applied to other models. Through this process, the fragility of neural networks when operating with adversarial attacks is universal and can be analyzed. The primary dataset is from the cifar-10 dataset, including ten classes of natural item images with RGB channels. The deep learning models are LeNet, ResNet18, and VGG16, which use the fast gradient sign method (FGSM). The attacked models generate incorrect samples, utilized in the other two models to demonstrate effective test performance. The result indicates that the attack on a specific neural network model cannot disturb other models.

References

[1] Chen Yu; Xing Yang; Haoli Xu, et al. Research Progress of Physical Adversarial Examples for Anti-Intelligent Detection//2024 5th International Seminar on Artificial Intelligence, Networking and Information Technology (AINIT). IEEE, 2024: 175-181.

[2] Yao Huang, Yinpeng Dong, Shouwei Ruan, et al. Towards Transferable Targeted 3D Adversarial Attack in the Physical World//Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition. 2024: 24512-24522.

[3] Linyu Tang, Lei Zhang. Robust Overfitting Does Matter: Test-Time Adversarial Purification With FGSM //Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition. 2024: 24347-24356.

[4] Ian J. Goodfellow, Jonathon Shlens, Christian Szegedy. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572, 2014.

[5] Bharati Yadav, Ajay Indian, Gaurav Meena. Recognizing Offline Devanagari Handwritten Characters Using Modified Lenet-5 Deep Neural Network. Procedia Computer Science, 2024, 235: 799-809.

[6] Serena Sunkari, Ashish Sangam, Venkata Sreeram P, et al. A refined ResNet18 architecture with Swish activation function for Diabetic Retinopathy classification. Biomedical Signal Processing and Control, 2024, 88: 105630. Dean&Francis Jin Xing

[7] Chittathuru Himala Praharsha, Alwin Poulose. CBAM VGG16: an efficient driver distraction classification using CBAM embedded VGG16 architecture. Computers in biology and medicine, 2024, 180: 108945.

[8] JIAWEI DU, Qin Shi, Joey Tianyi Zhou. Sequential subset matching for dataset distillation[J]. Advances in Neural Information Processing Systems, 2024, 36.

Downloads

Published

2024-12-31