• Home
  • Search
  • Optimized Adversarial Example With Classification Score Pattern Vulnerability Removed
  • Cite Icon4
  • https://doi.org/10.1109/access.2021.3110473Copy DOI Icon

Optimized Adversarial Example With Classification Score Pattern Vulnerability Removed

Show More
  • Abstract
  • Highlights & Summary
  • PDF
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

Neural networks provide excellent service on recognition tasks such as image recognition and speech recognition as well as for pattern analysis and other tasks in fields related to artificial intelligence. However, neural networks are vulnerable to adversarial examples. An adversarial example is a sample that is designed to be misclassified by a target model, although it poses no problem for recognition by humans, that is created by applying a minimal perturbation to a legitimate sample. Because the perturbation applied to the legitimate sample to create an adversarial example is optimized, the classification score for the target class has the characteristic of being similar to that for the legitimate class. This regularity occurs because minimal perturbations are applied only until the classification score for the target class is slightly higher than that for the legitimate class. Given the existence of this regularity in the classification scores, it is easy to detect an optimized adversarial example by looking for this pattern. However, the existing methods for generating optimized adversarial examples do not consider their weakness of allowing detectability by recognizing the pattern in the classification scores. To address this weakness, we propose an optimized adversarial example generation method in which the weakness due to the classification score pattern is removed. In the proposed method, a minimal perturbation is applied to a legitimate sample such that the classification score for the legitimate class is less than that for some of the other classes, and an optimized adversarial example is created with the pattern vulnerability removed. The results show that using 500 iterations, the proposed method can generate an optimized adversarial example that has a 100% attack success rate, with distortions of 2.81 and 2.23 for MNIST and Fashion-MNIST, respectively.

Loading PDF

Similar Papers
  • PDF
  • Research Article
  • Citations30

Classification score approach for detecting adversarial example in deep neural network

  • Nov 21, 2020
  • Multimedia Tools and Applications
  • Hyun Kwon +3
  • Research Article
  • Citations12

Audio adversarial detection through classification score on speech recognition systems

  • Dec 12, 2022
  • Computers & Security
  • Hyun Kwon +1
  • Research Article
  • Citations3

Priority Evasion Attack: An Adversarial Example That Considers the Priority of Attack on Each Classifier

  • Nov 01, 2022
  • IEICE Transactions on Information and Systems
  • Hyun Kwon +2
  • Research Article
  • Citations7

INOR—An Intelligent noise reduction method to defend against adversarial audio examples

  • Mar 12, 2020
  • Neurocomputing
  • Qingli Guo +6
  • Research Article

Adversarial Example Generation Method Based on Wavelet Transform

  • Feb 10, 2026
  • Information
  • Meng Bi +5
  • Book Chapter
  • Citations4

BeamAttack: Generating High-quality Textual Adversarial Examples Through Beam Search and Mixed Semantic Spaces

  • Jan 01, 2023
  • Hai Zhu +2
  • Research Article
  • Citations2

Adversarial Example Devastation and Detection on Speech Recognition System by Adding Random Noise

  • Jan 16, 2023
  • Journal of the Audio Engineering Society
  • Mingyu Dong +2
  • Research Article
  • Citations4

Evasion Attacks on Deep Learning-Based Helicopter Recognition Systems

  • Mar 22, 2024
  • Journal of Sensors
  • Jun Lee +4
  • Conference Article
  • Citations3

How Robust is Your Automatic Diagnosis Model?

  • Nov 01, 2019
  • Ke Wang +3
  • Conference Article
  • Citations11

Nickel to Lego

  • Nov 06, 2019
  • Joon Kuy Han +2
  • Research Article
  • Citations17

Generating adversarial examples via enhancing latent spatial features of benign traffic and preserving malicious functions

  • Dec 31, 2021
  • Neurocomputing
  • Rongqian Zhang +4
  • Conference Article
  • Citations206

Adversarial Deep Learning for Robust Detection of Binary Encoded Malware

  • May 01, 2018
  • Abdullah Al-Dujaili +3
  • Research Article
  • Citations3

Explanation-Guided Adversarial Example Attacks

  • Mar 26, 2024
  • Big Data Research
  • Anli Yan +4
  • Conference Article
  • Citations6

On Multiview Robustness of 3D Adversarial Attacks

  • Jul 26, 2020
  • Practice and Experience in Advanced Research Computing
  • Philip Yao +3
  • Conference Article
  • Citations9

Generating Adversarial Examples in Audio Classification with Generative Adversarial Network

  • Jul 26, 2022
  • Qiang Zhang +3
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.