Font Size: a A A

Research On Pixel Attack Algorithm Of Deep Neural Network

Posted on:2020-11-27Degree:MasterType:Thesis
Country:ChinaCandidate:T SuFull Text:PDF
GTID:2428330605980560Subject:Computer application technology
Abstract/Summary:PDF Full Text Request
Black box attack algorithm is an important method to test the robustness of deep learning algorithm.This paper mainly studies the pixel attack algorithm under the black box condition.However,the existing black box attack algorithm has pervasive problems,such as more queries and selecting difficulty of sensitive pixels.In this paper,a series of optimization algorithms are performed to solve the problem of black box attack.This paper proposes a black box attack optimization algorithm based on bilinear interpolation.First,our research redefined the black box attack problem as unconstrained optimization problem.Secondly,the loss function and the gradient calculation method of the optimization algorithm are redefined based on the decision information of neural network.Finally,the small disturbance pixels are randomly amplified by bilinear interpolation technology and add to the image,then Adam optimizer use it to search for the optimal perturbations.In this paper,massive experiments were carried out on the standard data set MNIST and cifar10.Compared with the most advanced algorithm,the query times of this algorithm were reduced by 2.5% and 4.9% respectively.This paper puts forward the black box attack optimization algorithm based on differential evolution,further reduce the number of queries on the basis of bilinear interpolation basis.To decrease initial search dimension of Adam,the algorithm firstly search image is sensitive to perturbations by using differential evolution before attack operation.On MNIST and cifar10 data set,the query can reduce up to 50.48% and 11.59% respectively while implements the effective black box to attack.For the problem of black target attack,this paper proposed base on adaptive parameter differential evolution of black box target optimization algorithm.The main control parameters of differential evolution are scaling factor and crossover probability.On the demand of the target attack,this paper promoted the calculation method of two parameters and combined optimization algorithm effectively realize the black box attack.Query frequency decreased by 19.85% and 0.95% comparing to the Auto Zoom target algorithm on MNIST and cifar10 data set.
Keywords/Search Tags:Deep Learning, Black-box Attack, Optimization Algorithm, Queries
PDF Full Text Request
Related items