CD-UAP: Class Discriminative Universal Adversarial Perturbation
Chaoning Zhang, Philipp Benz, Tooba Imtiaz, In-So Kweon
Abstract
A single universal adversarial perturbation (UAP) can be added to all natural images to change most of their predicted class labels. It is of high practical relevance for an attacker to have flexible control over the targeted classes to be attacked, however, the existing UAP method attacks samples from all classes. In this work, we propose a new universal attack method to generate a single perturbation that fools a target network to misclassify only a chosen group of classes, while having limited influence on the remaining classes. Since the proposed attack generates a universal adversarial perturbation that is discriminative to targeted and non-targeted classes, we term it class discriminative universal adversarial perturbation (CD-UAP). We propose one simple yet effective algorithm framework, under which we design and compare various loss function configurations tailored for the class discriminative universal attack. The proposed approach has been evaluated with extensive experiments on various benchmark datasets. Additionally, our proposed approach achieves state-of-the-art performance for the original task of UAP attacking all classes, which demonstrates the effectiveness of our approach.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e6669867-6bc1-40af-b8a1-68c73ed8a59aCited by top-tier papers12
- UDH: Universal Deep Hiding for Steganography, Watermarking, and Light Field MessagingChaoning Zhang, Philipp Benz, Adil Karjauv, Geng Sun et al.NeurIPS 2020 · 198 citations
- Universal Adversarial Perturbations Through the Lens of Deep Steganography: Towards a Fourier PerspectiveChaoning Zhang, Philipp Benz, Adil Karjauv, In So KweonAAAI 2021 · 50 citations
- Enhancing Generalization of Universal Adversarial Perturbation through Gradient AggregationXuannan Liu, Yaoyao Zhong, Yuhang Zhang, Lixiong Qin et al.ICCV 2023 · 42 citations
- Targeted Attack against Deep Neural Networks via Flipping Limited Weight BitsJiawang Bai, Baoyuan Wu, Yong Zhang, Yiming Li et al.ICLR 2021 · 29 citations
- Exploring Non-target Knowledge for Improving Ensemble Universal Adversarial AttacksJuanjuan Weng, Zhiming Luo, Zhun Zhong, Dazhen Lin et al.AAAI 2023 · 24 citations
Builds on1
Related papers
- Learning Universal Adversarial Perturbation by Adversarial ExampleMaosen Li, Yanhua Yang, Kun Wei, Xu Yang et al.AAAI 2022 · 44 citations
- Data-free Universal Adversarial Perturbation and Black-box AttackChaoning Zhang, Philipp Benz, Adil Karjauv, In So KweonICCV 2021 · 83 citations
- Defending Against Universal Perturbations With Shared Adversarial TrainingChaithanya Kumar Mummadi, Thomas Brox, Jan Hendrik MetzenICCV 2019 · 61 citations
- Universal Perturbation Attack Against Image RetrievalJie Li, Rongrong Ji, Hong Liu, Xiaopeng Hong et al.ICCV 2019 · 115 citations
- Over-the-Air Adversarial Flickering Attacks Against Video Recognition NetworksRoi Pony, Itay Naeh, Shie MannorCVPR 2021
