Generating Adversarial Examples with Shadow Model

Rui Zhang,Hui Xia,Chunqiang Hu,Cheng Zhang,Chao Liu,Fu Xiao
DOI: https://doi.org/10.1109/tii.2021.3139902
IF: 12.3
2022-01-01
IEEE Transactions on Industrial Informatics
Abstract:The reduction in the number of queries to the object model is a hot topic in the current research of black-box adversarial attack methods. To solve this problem, in this article, we propose generating adversarial examples with shadow model (GASM) that shifts the number of queries to the object model to the shadow model. The method first determines the shadow model based on the robustness and transferability of classifiers and fine-tunes the decision boundary of the shadow model by constructing adversarial datasets. Second, accesses the shadow model and constructs adversarial examples by maximizing the output probability of the targeted class (any class other than the current one) to modify the image gradient information. Finally, the results show that GASM has the strongest transferability and outperforms white-box attacks when AlexNet (MNIST), VGG-19 (CIFAR10), and MobileNet v2 (Tiny ImageNet) are selected as shadow models.
automation & control systems,computer science, interdisciplinary applications,engineering, industrial
What problem does this paper attempt to address?