Published January 6, 2021 | Version v 0.1
Journal article Open

FineFool: A Novel DNN Object Contour Attack on Image Recognition based on the Attention Perturbation Adversarial Technique

  • 1. Zhejiang University of Technolog
  • 2. Zhejiang University of Technology
  • 3. Zhejiang University

Description

Deep neural networks (DNNs) have various applications owing to their feature learning ability. However, recent studies have shown that DNNs are vulnerable to adversarial examples. Currently, research on the generation of adversarial examples primarily focuses on improving the attack success rate (ASR) while reducing the perturbation size. By visualizing of heat maps , previous works have found that the feature extraction effect of DNNs is owing to the precise location of object contours and the provision of the correct attention to those areas. Therefore, the perturbations in adversarial examples will weaken the location of object contours in deep hidden layers and reduce the attention scope of the object area, which will lead to successful attacks. Inspired by this observation, we propose FineFool, a novel adversarial attack based on the attention perturbation adversarial technique, which includes channel-spatial attention and pixel-spatial attention. The former reduces the area of concern using DNNs while the latter achieves the error location of the object contours. By using the attention perturbation adversarial technique to target positions that are more vulnerable in legitimate examples, FineFool achieves a higher ASR with fewer perturbations compared with that of state-of-the-art adversarial attacks. Extensive experiments are carried out on MNIST, CIFAR10, and ImageNet datasets against six models. The results show that FineFool can achieve the best performance compared with the six baselines. More specifically, the mean ASR values of untargeted/targeted attack are 99.23% and 98.26% for FineFool on all datasets, respectively, which is the highest under white-box attack situations.

Files

code.zip

Files (1.4 GB)

Name Size Download all
md5:3530ce617d0f19e441de220f0a958cc5
27.8 kB Preview Download
md5:c7cf3d498f453e9eeda7ed843e6fe435
654.6 MB Preview Download
md5:34fdd213a30cb0fbfcdc6bf7b65bdb8d
3.2 MB Preview Download
md5:ed7d4027651e3f22ca286d53ee4761a9
81.2 MB Preview Download
md5:13e1313cef4cc2cd94c0d9dec47e0f83
612.9 MB Preview Download
md5:012701ea305b18296e5941843262f01a
14.1 kB Preview Download