Procedural noise adversarial examples for black-box attacks on deep neural networks
File(s)1810.00470.pdf (5.1 MB)
Accepted version
Author(s)
Co, Kenneth Tan
Munoz Gonzalez, Luis
de Maupeou, Sixte
Lupu, Emil
Type
Conference Paper
Abstract
Deep Convolutional Networks (DCNs) have been shown to be vulnerable to adversarial examples—perturbed inputs specifically designed to produce intentional errors in the learning algorithms attest time. Existing input-agnostic adversarial perturbations exhibit interesting visual patterns that are currently unexplained. In this paper, we introduce a structured approach for generating Universal Adversarial Perturbations (UAPs) with procedural noise functions. Our approach unveils the systemic vulnerability of popular DCN models like Inception v3 and YOLO v3, with single noise patterns able to fool a model on up to 90% of the dataset. Procedural noise allows us to generate a distribution of UAPs with high universal evasion rates using only a few parameters. Additionally, we propose Bayesian optimization to efficiently learn procedural noise parameters to construct inexpensive untargeted black-box attacks. We demonstrate that it can achieve an average of less than 10 queries per successful attack, a 100-fold improvement on existing methods. We further motivate the use of input-agnostic defences to increase the stability of models to adversarial perturbations. The universality of our attacks suggests that DCN models may be sensitive to aggregations of low-level class-agnostic features. These findings give insight on the nature of some universal adversarial perturbations and how they could be generated in other applications.
Date Issued
2019-11
Date Acceptance
2019-06-23
Citation
2019 ACM SIGSAC Conference on Computer and Communications Security Proceedings, 2019, pp.275-289
Publisher
ACM
Start Page
275
End Page
289
Journal / Book Title
2019 ACM SIGSAC Conference on Computer and Communications Security Proceedings
Copyright Statement
© 2019 Copyright held by the owner/author(s). Publication rights licensed to the
Association for Computing Machinery
Association for Computing Machinery
Identifier
https://dl.acm.org/doi/abs/10.1145/3319535.3345660
Source
26th ACM Conference on Computer and Communications Security
Subjects
Science & Technology
Technology
Computer Science, Information Systems
Computer Science, Theory & Methods
Telecommunications
Computer Science
adversarial machine learning
Bayesian optimization
black-box attacks
deep neural networks
procedural noise
universal adversarial perturbations
cs.CR
cs.CR
stat.ML
Publication Status
Published
Start Date
2019-11-11
Finish Date
2019-11-15
Coverage Spatial
London
Date Publish Online
2019-11