欢迎访问《空军工程大学学报》官方网站!

咨询热线:029-84786242 RSS EMAIL-ALERT
改进的Mixup方法定向攻击图像分类模型
DOI:
作者:
作者单位:

作者简介:

通讯作者:

中图分类号:

TP751.1

基金项目:

国家自然科学基金(62171381)


An Improved Mixup Attack for Directed Attack Image Classification Models
Author:
Affiliation:

Fund Project:

  • 摘要
  • |
  • 图/表
  • |
  • 访问统计
  • |
  • 参考文献
  • |
  • 相似文献
  • |
  • 引证文献
  • |
  • 资源附件
  • |
  • 文章评论
    摘要:

    针对当前遥感图像分类领域的对抗性示例定向攻击研究较少、黑盒攻击能力较弱的问题,设计了一种改进的Mixup攻击的定向黑盒攻击方法。该方法旨在定向愚弄深度神经网络中的分类模型,发现其漏洞,使己方的高价值目标被检测为低价值或无价值目标。该方法首先是使用图像分类深度学习模型提取图像的浅层全局特征,通过改变输入图像像素,将输入干净图像的浅层特征向目标类图像浅层特征逼近,实现定向攻击。之后,为了提高攻击的迁移性,设计了一种自适应控制迭代步长的方法,提高迭代的效率。同时引入了模型级联的思想,使用多个不同架构的模型同时作为代理模型,使生成的对抗样本兼具多模型特征,提高攻击的迁移性。在多个遥感分类数据集上对多个模型进行测试的结果证明了本文方法的有效性。

    Abstract:

    In this paper,a directional attack black-box attack method named improved mixup attack (IMA) method is designed aimed at the current problems that researches on adversarial examples of targeted attacks are less,and black-box attack capability is very weak in remote sensing image classification.The method aims to directionally fool the classification model out of the deep neural network,discover its vulnerable parts,and enable our high-value target to be detected as a low or no-value target.The method,firstly,is used to extract the shallow global features of the image by an image classification deep learning model,and is used to realize the targeted attack for changing the input image pixels to approximate the shallow features of the input clean image to the target image.After that,an adaptive control of the iteration step size is designed to improve the efficiency of the iteration and the transferability of the attack.Simultaneously,the idea of model hierarchy is introduced by using multiple models with different architectures as surrogate models,so that the generated adversarial examples have both multi-model features to improve the transferability of the attack.Finally,several models are tested on several remote sensing classification datasets,and the experimental results show that the proposed method is valid.

    参考文献
    相似文献
    引证文献
引用本文

朱瑞,马时平,何林远,梅少辉.改进的Mixup方法定向攻击图像分类模型[J].空军工程大学学报,2025,26(1):32-41

复制
分享
文章指标
  • 点击次数:
  • 下载次数:
  • HTML阅读次数:
  • 引用次数:
历史
  • 收稿日期:
  • 最后修改日期:
  • 录用日期:
  • 在线发布日期: 2025-02-16
  • 出版日期: