基于双重引导的目标对抗攻击方法
孙月,张兴兰

Targeted adversarial attack method based on dual guidance
Yue SUN,Xinglan ZHANG
表 4 CIFAR10数据集上各类攻击方法攻击经过对抗训练的模型时的目标攻击成功率
Tab.4 Targeted ASRs of various attack methods on CIFAR10 dataset when attacking adversarial training models
攻击方法tASR/%
VGG16ResNet18Inv3DenseNetWideResNet
MIM16.9319.6631.0322.9122.06
Auto-PGD17.4828.0757.5944.1139.26
DIM35.1757.9769.9964.1667.42
TIM35.4332.0724.3930.1333.63
SIM25.0940.3661.1552.0552.96
VMI-FGSM25.8336.5558.9147.0946.63
DO-M-DI211.0226.6937.0430.8741.12
DeCowA15.4124.9628.4525.5130.16
IDAA38.7748.9566.7959.9149.07
LOGIT39.5550.1059.2951.3855.14
POTRIP29.0837.2848.2242.8940.67
AdvGAN4.0931.4835.9535.1341.44
本研究方法28.4272.7383.9975.5486.51