arXiv:2410.02043cs.CRcs.LG2024-10被引 2

测试6种对抗攻击对CNN模型的破坏力,发现迭代攻击更致命。

Impact of White-Box Adversarial Attacks on Convolutional Neural Networks

  • 对比6种白盒攻击,分析其提升错误率的能力差异。
  • 在MNIST等4个数据集上验证,攻击使准确率下降超50%。
  • 适合关注AI安全与防御的研究者阅读。

自动驾驶和医疗诊断等领域中,图像类机器学习模型的可靠性与安全性至关重要。本文全面研究了广泛应用于图像数据的卷积神经网络(CNN)对白盒对抗攻击的脆弱性。考察了快速梯度符号法(FGSM)、基本迭代法(BIM)、基于雅可比的显著性图攻击(JSMA)、Carlini & Wagner、投影梯度下降(PGD)和DeepFool等多种先进攻击方法对CNN性能指标(如损失、准确率)的影响,分析不同攻击在提升错误率方面的有效性差异,探究感知图像质量指标(如ERGAS、PSNR、SSIM、SAM)与分类性能的关系,并比较迭代攻击与单步攻击的效能。基于MNIST、CIFAR-10、CIFAR-100和Fashion_MNIST数据集,通过调整CNN超参数,系统评估各类攻击对模型性能的影响。研究揭示了CNN在对抗威胁下的脆弱性,指出了关键漏洞,强调了开发鲁棒防御机制的紧迫性,以保障CNN在真实场景中的可信部署。

原文摘要 · Abstract (English)

Autonomous vehicle navigation and healthcare diagnostics are among the many fields where the reliability and security of machine learning models for image data are critical. We conduct a comprehensive investigation into the susceptibility of Convolutional Neural Networks (CNNs), which are widely used for image data, to white-box adversarial attacks. We investigate the effects of various sophisticated attacks -- Fast Gradient Sign Method, Basic Iterative Method, Jacobian-based Saliency Map Attack, Carlini & Wagner, Projected Gradient Descent, and DeepFool -- on CNN performance metrics, (e.g., loss, accuracy), the differential efficacy of adversarial techniques in increasing error rates, the relationship between perceived image quality metrics (e.g., ERGAS, PSNR, SSIM, and SAM) and classification performance, and the comparative effectiveness of iterative versus single-step attacks. Using the MNIST, CIFAR-10, CIFAR-100, and Fashio_MNIST datasets, we explore the effect of different attacks on the CNNs performance metrics by varying the hyperparameters of CNNs. Our study provides insights into the robustness of CNNs against adversarial threats, pinpoints vulnerabilities, and underscores the urgent need for developing robust defense mechanisms to protect CNNs and ensuring their trustworthy deployment in real-world scenarios.

对抗攻击CNN安全模型鲁棒性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。