Low Frequency Sparse Adversarial Attack
Jiyuan Liu,Bingyi Lu,Mingkang Xiong,Tao Zhang,Huilin Xiong
DOI: https://doi.org/10.1016/j.cose.2023.103379
IF: 5.105
2023-01-01
Computers & Security
Abstract:Deep neural network (DNN) is found to be vulnerable to adversarial attacks. Gradient-based adversarial attacks usually craft perturbation on the whole pixels of input image, making them easier to be perceived or detected by the detection-based defenses, in the case of using large perturbation budget. In this paper, we present a new sparse approach to perturb image, which we call Robust Gradient-based Low Frequency search (RGLF). We show that RGLF provides a convenient way to modify any adversarial attack so that its imperceptibility can be improved significantly, not only to human eyes, but also to some popular detection-based defenses. Technically, RGLF first uses a robust gradient mask (RGM) to localize the semantic regions of input image, and then, applies a technique, called adaptive frequency search (AFS), to generate the low-frequency perturbations we expect, and finally, embeds the perturbations in the semantic regions. Extensive experiments are conducted to show that, i) the proposed RGLF technique can remarkably reduce the detection rates of the gradient-based adversarial attacks by 25%, 36%, and 30%, respectively for three SOTA detection-based defenses, namely, SBD, LiBRe, and SimCat; ii) The imperceptibility of the adversarial attacks modified by RGLF is improved significantly, even in the case of using large perturbation budget.