基于双重引导的目标对抗攻击方法
|
|
孙月,张兴兰
|
Targeted adversarial attack method based on dual guidance
|
|
Yue SUN,Xinglan ZHANG
|
|
| 表 4 CIFAR10数据集上各类攻击方法攻击经过对抗训练的模型时的目标攻击成功率 |
| Tab.4 Targeted ASRs of various attack methods on CIFAR10 dataset when attacking adversarial training models |
|
| 攻击方法 | tASR/% | | VGG16 | ResNet18 | Inv3 | DenseNet | WideResNet | | MIM | 16.93 | 19.66 | 31.03 | 22.91 | 22.06 | | Auto-PGD | 17.48 | 28.07 | 57.59 | 44.11 | 39.26 | | DIM | 35.17 | 57.97 | 69.99 | 64.16 | 67.42 | | TIM | 35.43 | 32.07 | 24.39 | 30.13 | 33.63 | | SIM | 25.09 | 40.36 | 61.15 | 52.05 | 52.96 | | VMI-FGSM | 25.83 | 36.55 | 58.91 | 47.09 | 46.63 | | DO-M-DI2 | 11.02 | 26.69 | 37.04 | 30.87 | 41.12 | | DeCowA | 15.41 | 24.96 | 28.45 | 25.51 | 30.16 | | IDAA | 38.77 | 48.95 | 66.79 | 59.91 | 49.07 | | LOGIT | 39.55 | 50.10 | 59.29 | 51.38 | 55.14 | | POTRIP | 29.08 | 37.28 | 48.22 | 42.89 | 40.67 | | AdvGAN | 4.09 | 31.48 | 35.95 | 35.13 | 41.44 | | 本研究方法 | 28.42 | 72.73 | 83.99 | 75.54 | 86.51 |
|
|
|