Boosting Black-box Adversarial Attack with a Better Convergence

Heng Yin,Jindong Wang,Yan Mi,Xiaoning Zhang
DOI: https://doi.org/10.1109/icmcce51767.2020.00272
2020-12-01
Abstract:While the neural network plays a significant role in image recognition, it's vulnerable to the adversarial examples, which is a potential threat to the deep learning systems. However, the adversarial examples can also be used to validate the effectiveness of the networks. And the transferability of the adversarial examples needed to be improved. Learning rate decay is a trick that is often used in the model training, and we apply this method into the generation of the adversarial examples. The Step Size Decay Iterative Fast Gradient Sign Method and Step Size Decay Momentum Iterative Fast Gradient Sign Method are proposed in this paper, which lead to better convergence and improve the attack performance of the adversarial examples on black-box models. Extensive experiments on ImageNet have validated the effectiveness of our methods.
What problem does this paper attempt to address?