基于双重引导的目标对抗攻击方法
|
|
孙月,张兴兰
|
Targeted adversarial attack method based on dual guidance
|
|
Yue SUN,Xinglan ZHANG
|
|
| 表 2 不同攻击方法在CIFAR10数据集上的目标攻击成功率 |
| Tab.2 Targeted ASRs of various attack methods on CIFAR10 dataset |
|
| 攻击方法 | tASR/% | | VGG16 | ResNet18 | Inv3 | DenseNet | WideResNet | 平均 | | MIM | 100.00 | 83.45 | 93.64 | 93.97 | 94.41 | 91.37 | | Auto-PGD | 100.00 | 73.68 | 86.68 | 87.33 | 87.74 | 83.86 | | DIM | 99.64 | 78.22 | 83.72 | 84.27 | 84.95 | 82.79 | | TIM | 83.66 | 29.71 | 26.82 | 26.20 | 29.08 | 27.95 | | SIM | 99.53 | 73.47 | 81.58 | 81.74 | 81.25 | 79.51 | | VMI-FGSM | 99.92 | 82.64 | 90.30 | 91.32 | 90.72 | 88.75 | | DO-M-DI2 | 95.09 | 55.12 | 67.46 | 68.25 | 72.12 | 65.74 | | DeCowA | 98.93 | 68.76 | 71.40 | 74.86 | 77.08 | 73.03 | | IDAA | 99.04 | 86.77 | 90.75 | 89.78 | 91.74 | 89.76 | | LOGIT | 99.75 | 74.49 | 78.11 | 80.28 | 85.25 | 79.53 | | POTRIP | 93.22 | 51.32 | 53.58 | 54.17 | 55.64 | 53.68 | | AdvGAN | 97.08 | 39.68 | 61.08 | 70.28 | 65.34 | 59.10 | | 本研究方法 | 98.31 | 93.52 | 96.01 | 97.09 | 97.66 | 96.07 |
|
|
|