Imperceptible and Sparse Adversarial Attacks Via a Dual-Population-Based Constrained Evolutionary Algorithm

Ye Tian,Jingwen Pan,Shangshang Yang,Xingyi Zhang,Shuping He,Yaochu Jin
DOI: https://doi.org/10.1109/tai.2022.3168038
2023-01-01
IEEE Transactions on Artificial Intelligence
Abstract:The sparse adversarial attack has attracted increasing attention due to the merit of a low attack cost via changing a small number of pixels. However, the generated adversarial examples are easily detected in vision since the perturbation to each pixel is relatively large. To achieve imperceptible and sparse adversarial attacks, this article formulates a bi-objective constrained optimization problem, simultaneously minimizing the $\ell _{0}$ and $\ell _{2}$ distances to the original image, and proposes a dual-population-based constrained evolutionary algorithm to solve it. The proposed method solves the optimization problem by evolving two populations, where one population is responsible for finding feasible solutions (i.e., successful attacks) and the other one is to minimize both the $\ell _{0}$ and $\ell _{2}$ distances. Moreover, a population initialization strategy and two genetic operators are customized to accelerate the convergence speed. Experimental results indicate that the proposed method can achieve high success rates with low attack costs, and strikes a better balance between the $\ell _{0}$ and $\ell _{2}$ distances than state-of-the-art methods.
What problem does this paper attempt to address?