Adversarial Attacks on Regression Systems Via Gradient Optimization

Xiangyin Kong,Zhiqiang Ge
DOI: https://doi.org/10.1109/tsmc.2023.3302838
2023-01-01
Abstract:Adversarial attack can fabricate imperceptible fake samples to cheat a well-trained artificial intelligence (AI) model, and it has shown strong destructive power in many classification tasks. In real-world AI applications, there is another popular kind of machine learning paradigm-regression. The threats of adversarial attack may also exist in the regression scenario, however, the research on the adversarial vulnerability of the regression model has been basically neglected. This article first systematically explores the adversarial attack on regression problems. Starting from analyzing the difference between the attacking classification models and regression systems, we show the existing attack framework of classification problems is unsuitable for attacking regression systems. Then, we discuss the essence of regression tasks and design an appropriate attack objective for regression problems. After that, we propose two algorithms with different properties based on gradient optimization to achieve the attack objective. The proposed attack methods are evaluated on three real-world regression cases, and the results show that our attacks can successfully make the prediction deviate a lot from its original value by only exerting a tiny perturbation on the inputs. Finally, we conduct further experiments and analyses to discuss the effectiveness and characteristics of the proposed methods from various perspectives.
What problem does this paper attempt to address?