SAL: Salient Adversarial Attack with LRP Refinement

Xinlei Gao,Jing Liu
DOI: https://doi.org/10.1007/978-3-031-44192-9_13
2023-01-01
Abstract:Deep Neural Networks (DNNs) are susceptible to attacks by adversarial examples, which could cause serious consequences in safety-critical systems. Towards recent studies on generating efficient adversarial examples, how to enhance the imperceptibility of adversarial examples has been an issue worth more investigating. In this paper, we propose a novel salient adversarial attack method based on Layer-Wise Relevance Propagation (LRP), named SAL, which restricts perturbations to salient regions and subsequently refines them using the LRP interpretation algorithm, reducing perturbations to some pixel points. We conduct sufficient experiments on the ImageNet-Compatible dataset. Experiment results demonstrate that our method is capable of generating higher imperceptibility adversarial examples in quite less time, compared to the representative PerC-AL method. Besides, the robustness and transferability of our method are validated to perform better than the baseline methods.
What problem does this paper attempt to address?