Matches in SemOpenAlex for { <https://semopenalex.org/work/W4293761272> ?p ?o ?g. }
- W4293761272 endingPage "11036" @default.
- W4293761272 startingPage "11019" @default.
- W4293761272 abstract "Recent researchers have shown that deep neural networks (DNNs) are vulnerable to adversarial exemplars, making them unsuitable for security-critical applications. Transferability of adversarial examples is crucial for attacking black-box models, which facilitates adversarial attacks in more practical scenarios. We propose a novel adversarial attack with high transferability. Unlike existing attacks that directly modify the input pixels, our attack is executed in the feature space. More specifically, we corrupt the abstract features by maximizing the feature distance between the adversarial example and clean images with a perceptual similarity network, inducing model misclassification. In addition, we apply a spectral transformation to the input, thus narrowing the search space in the frequency domain to enhance the transferability of adversarial examples. The disruption of crucial features in a specific frequency component achieves greater transferability. Extensive evaluations illustrate that our approach is easily compatible with many existing frameworks for transfer attacks and can significantly improve the baseline performance of black-box attacks. Moreover, we can obtain a higher fooling rate even if the model has a defense technique. We achieve a maximum black-box fooling rate of 61.70% on the defense model. Our work indicates that existing pixel space defense techniques are difficult to guarantee the robustness of the feature space, and the feature space from a frequency perspective is promising for developing more robust models." @default.
- W4293761272 created "2022-08-31" @default.
- W4293761272 creator A5003198271 @default.
- W4293761272 creator A5026287089 @default.
- W4293761272 creator A5052391925 @default.
- W4293761272 creator A5079590894 @default.
- W4293761272 creator A5086360069 @default.
- W4293761272 creator A5090304311 @default.
- W4293761272 date "2022-08-29" @default.
- W4293761272 modified "2023-10-15" @default.
- W4293761272 title "Toward feature space adversarial attack in the frequency domain" @default.
- W4293761272 cites W1849277567 @default.
- W4293761272 cites W2132984323 @default.
- W4293761272 cites W2183341477 @default.
- W4293761272 cites W2194775991 @default.
- W4293761272 cites W2243397390 @default.
- W4293761272 cites W2543927648 @default.
- W4293761272 cites W2603766943 @default.
- W4293761272 cites W2604505099 @default.
- W4293761272 cites W2746600820 @default.
- W4293761272 cites W2774018344 @default.
- W4293761272 cites W2774644650 @default.
- W4293761272 cites W2776107444 @default.
- W4293761272 cites W2799194071 @default.
- W4293761272 cites W2895097814 @default.
- W4293761272 cites W2896078964 @default.
- W4293761272 cites W2947129602 @default.
- W4293761272 cites W2949789602 @default.
- W4293761272 cites W2962785568 @default.
- W4293761272 cites W2962847335 @default.
- W4293761272 cites W2963446712 @default.
- W4293761272 cites W2963821229 @default.
- W4293761272 cites W2963857521 @default.
- W4293761272 cites W2964261768 @default.
- W4293761272 cites W2964301649 @default.
- W4293761272 cites W2965496811 @default.
- W4293761272 cites W2977099891 @default.
- W4293761272 cites W2984699060 @default.
- W4293761272 cites W2991496458 @default.
- W4293761272 cites W3034175346 @default.
- W4293761272 cites W3035579498 @default.
- W4293761272 cites W3106050153 @default.
- W4293761272 cites W3167976421 @default.
- W4293761272 doi "https://doi.org/10.1002/int.23031" @default.
- W4293761272 hasPublicationYear "2022" @default.
- W4293761272 type Work @default.
- W4293761272 citedByCount "1" @default.
- W4293761272 countsByYear W42937612722023 @default.
- W4293761272 crossrefType "journal-article" @default.
- W4293761272 hasAuthorship W4293761272A5003198271 @default.
- W4293761272 hasAuthorship W4293761272A5026287089 @default.
- W4293761272 hasAuthorship W4293761272A5052391925 @default.
- W4293761272 hasAuthorship W4293761272A5079590894 @default.
- W4293761272 hasAuthorship W4293761272A5086360069 @default.
- W4293761272 hasAuthorship W4293761272A5090304311 @default.
- W4293761272 hasConcept C104317684 @default.
- W4293761272 hasConcept C119857082 @default.
- W4293761272 hasConcept C124101348 @default.
- W4293761272 hasConcept C138885662 @default.
- W4293761272 hasConcept C140331021 @default.
- W4293761272 hasConcept C153180895 @default.
- W4293761272 hasConcept C154945302 @default.
- W4293761272 hasConcept C185592680 @default.
- W4293761272 hasConcept C19118579 @default.
- W4293761272 hasConcept C2776401178 @default.
- W4293761272 hasConcept C2984842247 @default.
- W4293761272 hasConcept C31972630 @default.
- W4293761272 hasConcept C37736160 @default.
- W4293761272 hasConcept C41008148 @default.
- W4293761272 hasConcept C41895202 @default.
- W4293761272 hasConcept C50644808 @default.
- W4293761272 hasConcept C55493867 @default.
- W4293761272 hasConcept C61272859 @default.
- W4293761272 hasConcept C63479239 @default.
- W4293761272 hasConcept C83665646 @default.
- W4293761272 hasConcept C94966114 @default.
- W4293761272 hasConceptScore W4293761272C104317684 @default.
- W4293761272 hasConceptScore W4293761272C119857082 @default.
- W4293761272 hasConceptScore W4293761272C124101348 @default.
- W4293761272 hasConceptScore W4293761272C138885662 @default.
- W4293761272 hasConceptScore W4293761272C140331021 @default.
- W4293761272 hasConceptScore W4293761272C153180895 @default.
- W4293761272 hasConceptScore W4293761272C154945302 @default.
- W4293761272 hasConceptScore W4293761272C185592680 @default.
- W4293761272 hasConceptScore W4293761272C19118579 @default.
- W4293761272 hasConceptScore W4293761272C2776401178 @default.
- W4293761272 hasConceptScore W4293761272C2984842247 @default.
- W4293761272 hasConceptScore W4293761272C31972630 @default.
- W4293761272 hasConceptScore W4293761272C37736160 @default.
- W4293761272 hasConceptScore W4293761272C41008148 @default.
- W4293761272 hasConceptScore W4293761272C41895202 @default.
- W4293761272 hasConceptScore W4293761272C50644808 @default.
- W4293761272 hasConceptScore W4293761272C55493867 @default.
- W4293761272 hasConceptScore W4293761272C61272859 @default.
- W4293761272 hasConceptScore W4293761272C63479239 @default.
- W4293761272 hasConceptScore W4293761272C83665646 @default.
- W4293761272 hasConceptScore W4293761272C94966114 @default.
- W4293761272 hasFunder F4320321001 @default.