• Cite Icon23
  • https://doi.org/10.1109/tc.2021.3065172Copy DOI Icon

FAWA: Fast Adversarial Watermark Attack

Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

Recently, adversarial attacks have shown to lead the state-of-the-art deep neural networks (DNNs) to misclassification. However, most adversarial attacks are generated according to whether they are perceptual to human visual system, measured by geometric metrics such as the l2-norm, which ignores the common watermarks in cyber-physical systems. In this paper, we propose a fast adversarial watermark attack (FAWA) method based on fast differential evolution technique, which optimally superimposes a watermark on an image to fool DNNs. We also attempt to explain the reason why the attack is successful and propose two hypotheses on the vulnerability of DNN classifiers and the influence of the watermark attack on higher-layer features extraction respectively. In addition, we propose two countermeasure methods against FAWA based on random rotation and median filtering respectively. Experimental results show that our method achieves 41.3% success rate in fooling VGG-16 and have good transferability. Our approach is also shown to be effective in deceiving deep learning as a service (DLaaS) systems as well as the physical world. The proposed FAWA, hypotheses, and the countermeasure methods, provide a timely help for DNN designers to gain some knowledge of model vulnerability while designing DNN classifiers and related DLaaS applications.

Similar Papers
  • Research Article
  • Citations3

Adversarial attack method against image classification based on haze perturbation

  • Feb 01, 2023
  • SCIENTIA SINICA Informationis
  • 伟 冯 +3
  • Research Article
  • Citations10

Sparsity Turns Adversarial: Energy and Latency Attacks on Deep Neural Networks

  • Oct 02, 2020
  • IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems
  • Sarada Krithivasan +2
  • Research Article

Towards Patch-Based Noise Compression for Adversarial Attack Against Transformer-Based Visual Tracking

  • Jan 01, 2026
  • IEEE Transactions on Information Forensics and Security
  • Peng Gao +6
  • PDF
  • Research Article
  • Citations8

A CMA-ES-Based Adversarial Attack on Black-Box Deep Neural Networks

  • Jan 01, 2019
  • IEEE Access
  • Xiaohui Kuang +5
  • Conference Article

Evaluation of Adversarial Attacks Based on DL in Communication Networks

  • Nov 01, 2020
  • Zhida Bao +1
  • Conference Article

Classification of Bisyllabic Lexical Stress Patterns Using Deep Neural Networks

  • Jan 01, 2016
  • Mostafa Shahin +1
  • Book Chapter

IGAff: Benchmarking Adversarial Iterative and Genetic Affine Algorithms on Deep Neural Networks

  • Oct 21, 2025
  • Frontiers in artificial intelligence and applications
  • Sebastian-Vasile Echim +3
  • Research Article
  • Citations8

Adversarial Robustness of Deep Convolutional Neural Network-based Image Recognition Models: A Review

  • Aug 28, 2021
  • 雷达学报
  • Hao Sun +4
  • PDF
  • Research Article
  • Citations21

Probabilistic Analysis of Targeted Attacks Using Transform-Domain Adversarial Examples

  • Jan 01, 2020
  • IEEE Access
  • Zakia Yahya +3
  • Research Article
  • Citations2

General Sparse Adversarial Attack Method for SAR Images Based on Keypoints

  • Oct 01, 2025
  • IEEE Transactions on Aerospace and Electronic Systems
  • Fei Gao +5
  • Research Article
  • Citations10

Self-adaptive logit balancing for deep neural network robustness: Defence and detection of adversarial attacks

  • Feb 17, 2023
  • Neurocomputing
  • Jiefei Wei +2
  • Research Article
  • Citations10

CardioDefense: Defending against adversarial attack in ECG classification with adversarial distillation training

  • Jan 05, 2024
  • Biomedical Signal Processing and Control
  • Jiahao Shao +5
  • Research Article
  • Citations22

Adversarial Sample Attack and Defense Method for Encrypted Traffic Data

  • Oct 01, 2022
  • IEEE Transactions on Intelligent Transportation Systems
  • Yi Ding +5
  • Research Article
  • Citations5

Masking and purifying inputs for blocking textual adversarial attacks

  • Aug 16, 2023
  • Information Sciences
  • Huan Zhang +6
  • Research Article
  • Citations17

Omni: automated ensemble with unexpected models against adversarial evasion attack

  • Nov 30, 2021
  • Empirical Software Engineering
  • Rui Shu +3
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.