arXiv:2411.04772cs.CRcs.AI2024-11被引 1

用注意力掩码提升对抗攻击的隐蔽性与效率,绕过AI安全检测。

Attention Masks Help Adversarial Attacks to Bypass Safety Detectors

  • 基于自监督X-UNet生成动态注意力掩码引导攻击。
  • 在MNIST和CIFAR-10上实现更隐蔽、更快的对抗样本。
  • 适合研究对抗攻击绕过安全检测机制的学者参考。

尽管对抗攻击方法取得进展,现有针对XAI监控器的攻击仍易被发现且速度较慢。本文提出一种自适应注意力掩码生成框架,实现隐蔽、可解释且高效的PGD图像分类对抗攻击。具体地,采用突变XAI混合与多任务自监督X-UNet生成注意力掩码,指导PGD攻击。在MNIST(MLP)和CIFAR-10(AlexNet)上的实验表明,本系统在隐蔽性、效率与可解释性之间达到更好平衡,优于基准方法PGD、Sparsefool及SOTA SINIFGSM,能有效欺骗当前最先进的防御型分类器。

原文摘要 · Abstract (English)

Despite recent research advancements in adversarial attack methods, current approaches against XAI monitors are still discoverable and slower. In this paper, we present an adaptive framework for attention mask generation to enable stealthy, explainable and efficient PGD image classification adversarial attack under XAI monitors. Specifically, we utilize mutation XAI mixture and multitask self-supervised X-UNet for attention mask generation to guide PGD attack. Experiments on MNIST (MLP), CIFAR-10 (AlexNet) have shown that our system can outperform benchmark PGD, Sparsefool and SOTA SINIFGSM in balancing among stealth, efficiency and explainability which is crucial for effectively fooling SOTA defense protected classifiers.

对抗攻击注意力掩码XAI安全检测

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。