Exploring Gaps in DeepFool inSearch of More Effective Adversarial Perturbations
Adversarial examples are inputs subtly perturbed to produce a wrong prediction in machine learning models, while remaining perceptually similar to the original input. To find adversarial examples, some attack strategies rely on linear approximations of different properties of the models. This opens...
| Autores: | , , |
|---|---|
| Tipo de recurso: | artículo |
| Estado: | Versión publicada |
| Fecha de publicación: | 2021 |
| País: | España |
| Institución: | Basque Center for Applied Mathematics (BCAM) |
| Repositorio: | BIRD. BCAM's Institutional Repository Data |
| OAI Identifier: | oai:bird.bcamath.org:20.500.11824/1281 |
| Acceso en línea: | http://hdl.handle.net/20.500.11824/1281 https://doi.org/10.1007/978-3-030-64580-9_18 |
| Access Level: | acceso abierto |
| Palabra clave: | Adversarial examples DeepFool Robust machine learning |
| id |
ES_4dfcf5faa50cc53e504bfa53d1145718 |
|---|---|
| oai_identifier_str |
oai:bird.bcamath.org:20.500.11824/1281 |
| network_acronym_str |
ES |
| network_name_str |
España |
| repository_id_str |
|
| spelling |
Exploring Gaps in DeepFool inSearch of More Effective Adversarial PerturbationsVadillo, J.Santana, R.Lozano, J.A.Adversarial examplesDeepFoolRobust machine learningAdversarial examples are inputs subtly perturbed to produce a wrong prediction in machine learning models, while remaining perceptually similar to the original input. To find adversarial examples, some attack strategies rely on linear approximations of different properties of the models. This opens a number of questions related to the accuracy of such approximations. In this paper we focus on DeepFool, a state-of-the-art attack algorithm, which is based on efficiently approximating the decision space of the target classifier to find the minimal perturbation needed to fool the model. The objective of this paper is to analyze the feasibility of finding inaccuracies in the linear approximation of DeepFool, with the aim of studying whether they can be used to increase the effectiveness of the attack. We introduce two strategies to efficiently explore gaps in the approximation of the decision boundaries, and evaluate our approach in a speech command classification task.IT1244-19 PRE_2019_1_0128 TIN2016-78365-R PID2019-104966GB-I00 FPU19/03231202120212021info:eu-repo/semantics/articleinfo:eu-repo/semantics/publishedVersionapplication/pdfhttp://hdl.handle.net/20.500.11824/1281https://doi.org/10.1007/978-3-030-64580-9_18reponame:BIRD. BCAM's Institutional Repository Datainstname:Basque Center for Applied Mathematics (BCAM)Inglésinfo:eu-repo/grantAgreement/MINECO//SEV-2017-0718info:eu-repo/grantAgreement/Gobierno Vasco/BERC/BERC.2018-2021info:eu-repo/grantAgreement/Gobierno Vasco/ELKARTEK/Reconocimiento-NoComercial-CompartirIgual 3.0 Españahttp://creativecommons.org/licenses/by-nc-sa/3.0/es/info:eu-repo/semantics/openAccessoai:bird.bcamath.org:20.500.11824/12812026-06-19T12:47:47Z |
| dc.title.none.fl_str_mv |
Exploring Gaps in DeepFool inSearch of More Effective Adversarial Perturbations |
| title |
Exploring Gaps in DeepFool inSearch of More Effective Adversarial Perturbations |
| spellingShingle |
Exploring Gaps in DeepFool inSearch of More Effective Adversarial Perturbations Vadillo, J. Adversarial examples DeepFool Robust machine learning |
| title_short |
Exploring Gaps in DeepFool inSearch of More Effective Adversarial Perturbations |
| title_full |
Exploring Gaps in DeepFool inSearch of More Effective Adversarial Perturbations |
| title_fullStr |
Exploring Gaps in DeepFool inSearch of More Effective Adversarial Perturbations |
| title_full_unstemmed |
Exploring Gaps in DeepFool inSearch of More Effective Adversarial Perturbations |
| title_sort |
Exploring Gaps in DeepFool inSearch of More Effective Adversarial Perturbations |
| dc.creator.none.fl_str_mv |
Vadillo, J. Santana, R. Lozano, J.A. |
| author |
Vadillo, J. |
| author_facet |
Vadillo, J. Santana, R. Lozano, J.A. |
| author_role |
author |
| author2 |
Santana, R. Lozano, J.A. |
| author2_role |
author author |
| dc.subject.none.fl_str_mv |
Adversarial examples DeepFool Robust machine learning |
| topic |
Adversarial examples DeepFool Robust machine learning |
| description |
Adversarial examples are inputs subtly perturbed to produce a wrong prediction in machine learning models, while remaining perceptually similar to the original input. To find adversarial examples, some attack strategies rely on linear approximations of different properties of the models. This opens a number of questions related to the accuracy of such approximations. In this paper we focus on DeepFool, a state-of-the-art attack algorithm, which is based on efficiently approximating the decision space of the target classifier to find the minimal perturbation needed to fool the model. The objective of this paper is to analyze the feasibility of finding inaccuracies in the linear approximation of DeepFool, with the aim of studying whether they can be used to increase the effectiveness of the attack. We introduce two strategies to efficiently explore gaps in the approximation of the decision boundaries, and evaluate our approach in a speech command classification task. |
| publishDate |
2021 |
| dc.date.none.fl_str_mv |
2021 2021 2021 |
| dc.type.none.fl_str_mv |
info:eu-repo/semantics/article info:eu-repo/semantics/publishedVersion |
| format |
article |
| status_str |
publishedVersion |
| dc.identifier.none.fl_str_mv |
http://hdl.handle.net/20.500.11824/1281 https://doi.org/10.1007/978-3-030-64580-9_18 |
| url |
http://hdl.handle.net/20.500.11824/1281 https://doi.org/10.1007/978-3-030-64580-9_18 |
| dc.language.none.fl_str_mv |
Inglés |
| language_invalid_str_mv |
Inglés |
| dc.relation.none.fl_str_mv |
info:eu-repo/grantAgreement/MINECO//SEV-2017-0718 info:eu-repo/grantAgreement/Gobierno Vasco/BERC/BERC.2018-2021 info:eu-repo/grantAgreement/Gobierno Vasco/ELKARTEK/ |
| dc.rights.none.fl_str_mv |
Reconocimiento-NoComercial-CompartirIgual 3.0 España http://creativecommons.org/licenses/by-nc-sa/3.0/es/ info:eu-repo/semantics/openAccess |
| rights_invalid_str_mv |
Reconocimiento-NoComercial-CompartirIgual 3.0 España http://creativecommons.org/licenses/by-nc-sa/3.0/es/ |
| eu_rights_str_mv |
openAccess |
| dc.format.none.fl_str_mv |
application/pdf |
| dc.source.none.fl_str_mv |
reponame:BIRD. BCAM's Institutional Repository Data instname:Basque Center for Applied Mathematics (BCAM) |
| instname_str |
Basque Center for Applied Mathematics (BCAM) |
| reponame_str |
BIRD. BCAM's Institutional Repository Data |
| collection |
BIRD. BCAM's Institutional Repository Data |
| repository.name.fl_str_mv |
|
| repository.mail.fl_str_mv |
|
| _version_ |
1869407727619407872 |
| score |
15.301603 |