Exploring Gaps in DeepFool inSearch of More Effective Adversarial Perturbations

Adversarial examples are inputs subtly perturbed to produce a wrong prediction in machine learning models, while remaining perceptually similar to the original input. To find adversarial examples, some attack strategies rely on linear approximations of different properties of the models. This opens...

Descripción completa

Detalles Bibliográficos
Autores: Vadillo, J., Santana, R., Lozano, J.A.
Tipo de recurso: artículo
Estado:Versión publicada
Fecha de publicación:2021
País:España
Institución:Basque Center for Applied Mathematics (BCAM)
Repositorio:BIRD. BCAM's Institutional Repository Data
OAI Identifier:oai:bird.bcamath.org:20.500.11824/1281
Acceso en línea:http://hdl.handle.net/20.500.11824/1281
https://doi.org/10.1007/978-3-030-64580-9_18
Access Level:acceso abierto
Palabra clave:Adversarial examples
DeepFool
Robust machine learning
id ES_4dfcf5faa50cc53e504bfa53d1145718
oai_identifier_str oai:bird.bcamath.org:20.500.11824/1281
network_acronym_str ES
network_name_str España
repository_id_str
spelling Exploring Gaps in DeepFool inSearch of More Effective Adversarial PerturbationsVadillo, J.Santana, R.Lozano, J.A.Adversarial examplesDeepFoolRobust machine learningAdversarial examples are inputs subtly perturbed to produce a wrong prediction in machine learning models, while remaining perceptually similar to the original input. To find adversarial examples, some attack strategies rely on linear approximations of different properties of the models. This opens a number of questions related to the accuracy of such approximations. In this paper we focus on DeepFool, a state-of-the-art attack algorithm, which is based on efficiently approximating the decision space of the target classifier to find the minimal perturbation needed to fool the model. The objective of this paper is to analyze the feasibility of finding inaccuracies in the linear approximation of DeepFool, with the aim of studying whether they can be used to increase the effectiveness of the attack. We introduce two strategies to efficiently explore gaps in the approximation of the decision boundaries, and evaluate our approach in a speech command classification task.IT1244-19 PRE_2019_1_0128 TIN2016-78365-R PID2019-104966GB-I00 FPU19/03231202120212021info:eu-repo/semantics/articleinfo:eu-repo/semantics/publishedVersionapplication/pdfhttp://hdl.handle.net/20.500.11824/1281https://doi.org/10.1007/978-3-030-64580-9_18reponame:BIRD. BCAM's Institutional Repository Datainstname:Basque Center for Applied Mathematics (BCAM)Inglésinfo:eu-repo/grantAgreement/MINECO//SEV-2017-0718info:eu-repo/grantAgreement/Gobierno Vasco/BERC/BERC.2018-2021info:eu-repo/grantAgreement/Gobierno Vasco/ELKARTEK/Reconocimiento-NoComercial-CompartirIgual 3.0 Españahttp://creativecommons.org/licenses/by-nc-sa/3.0/es/info:eu-repo/semantics/openAccessoai:bird.bcamath.org:20.500.11824/12812026-06-19T12:47:47Z
dc.title.none.fl_str_mv Exploring Gaps in DeepFool inSearch of More Effective Adversarial Perturbations
title Exploring Gaps in DeepFool inSearch of More Effective Adversarial Perturbations
spellingShingle Exploring Gaps in DeepFool inSearch of More Effective Adversarial Perturbations
Vadillo, J.
Adversarial examples
DeepFool
Robust machine learning
title_short Exploring Gaps in DeepFool inSearch of More Effective Adversarial Perturbations
title_full Exploring Gaps in DeepFool inSearch of More Effective Adversarial Perturbations
title_fullStr Exploring Gaps in DeepFool inSearch of More Effective Adversarial Perturbations
title_full_unstemmed Exploring Gaps in DeepFool inSearch of More Effective Adversarial Perturbations
title_sort Exploring Gaps in DeepFool inSearch of More Effective Adversarial Perturbations
dc.creator.none.fl_str_mv Vadillo, J.
Santana, R.
Lozano, J.A.
author Vadillo, J.
author_facet Vadillo, J.
Santana, R.
Lozano, J.A.
author_role author
author2 Santana, R.
Lozano, J.A.
author2_role author
author
dc.subject.none.fl_str_mv Adversarial examples
DeepFool
Robust machine learning
topic Adversarial examples
DeepFool
Robust machine learning
description Adversarial examples are inputs subtly perturbed to produce a wrong prediction in machine learning models, while remaining perceptually similar to the original input. To find adversarial examples, some attack strategies rely on linear approximations of different properties of the models. This opens a number of questions related to the accuracy of such approximations. In this paper we focus on DeepFool, a state-of-the-art attack algorithm, which is based on efficiently approximating the decision space of the target classifier to find the minimal perturbation needed to fool the model. The objective of this paper is to analyze the feasibility of finding inaccuracies in the linear approximation of DeepFool, with the aim of studying whether they can be used to increase the effectiveness of the attack. We introduce two strategies to efficiently explore gaps in the approximation of the decision boundaries, and evaluate our approach in a speech command classification task.
publishDate 2021
dc.date.none.fl_str_mv 2021
2021
2021
dc.type.none.fl_str_mv info:eu-repo/semantics/article
info:eu-repo/semantics/publishedVersion
format article
status_str publishedVersion
dc.identifier.none.fl_str_mv http://hdl.handle.net/20.500.11824/1281
https://doi.org/10.1007/978-3-030-64580-9_18
url http://hdl.handle.net/20.500.11824/1281
https://doi.org/10.1007/978-3-030-64580-9_18
dc.language.none.fl_str_mv Inglés
language_invalid_str_mv Inglés
dc.relation.none.fl_str_mv info:eu-repo/grantAgreement/MINECO//SEV-2017-0718
info:eu-repo/grantAgreement/Gobierno Vasco/BERC/BERC.2018-2021
info:eu-repo/grantAgreement/Gobierno Vasco/ELKARTEK/
dc.rights.none.fl_str_mv Reconocimiento-NoComercial-CompartirIgual 3.0 España
http://creativecommons.org/licenses/by-nc-sa/3.0/es/
info:eu-repo/semantics/openAccess
rights_invalid_str_mv Reconocimiento-NoComercial-CompartirIgual 3.0 España
http://creativecommons.org/licenses/by-nc-sa/3.0/es/
eu_rights_str_mv openAccess
dc.format.none.fl_str_mv application/pdf
dc.source.none.fl_str_mv reponame:BIRD. BCAM's Institutional Repository Data
instname:Basque Center for Applied Mathematics (BCAM)
instname_str Basque Center for Applied Mathematics (BCAM)
reponame_str BIRD. BCAM's Institutional Repository Data
collection BIRD. BCAM's Institutional Repository Data
repository.name.fl_str_mv
repository.mail.fl_str_mv
_version_ 1869407727619407872
score 15.301603