Adversarial Image Generation via Entropy-Enhanced Noise
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing adversarial attack methods on deep neural networks (DNNs) are ineffective when the target network employs defense mechanisms, as the noise features in generated adversarial images are too obvious, making it difficult for the attacks to succeed and thus reducing security.
Innovation Solution
A black box attack method is proposed, where a reference model classification-equivalent to the target classification model is constructed to generate adversarial images with enhanced noise entropy, making it difficult for the target classification model to recognize the adversarial samples without affecting human perception.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional adversarial attack methods are used to generate adversarial images, then the attack can be implemented, but the noise features are too obvious making the attack ineffective against defended networks
Solution Approach 1:
The patent transforms the noise generation process by changing parameters from direct gradient-based noise to entropy-enhanced noise. The adversarial model increases the information entropy of the noise, making it more random and less detectable while maintaining attack effectiveness. This parameter change in noise characteristics resolves the contradiction between attack effectiveness and noise obviousness.
Solution Approach 2:
The patent introduces an adversarial model as an intermediary between the target network and the adversarial examples. This intermediary processes and transforms the noise through entropy enhancement, acting as a mediator that obscures the noise features while preserving the adversarial properties. The intermediary hides the direct connection between the attack and the obvious noise patterns.
2Ease of manufacture
If noise is added to make the image imperceptible to humans, then human perception is maintained, but the classification accuracy of the target model must be reduced
Solution Approach 1:
The patent applies different noise characteristics to different regions and aspects of the image. The entropy-enhanced noise is distributed in a way that maintains local imperceptibility to humans while collectively affecting the model's classification accuracy. The local quality of noise is optimized to be imperceptible individually but effective collectively against the model.
Data Source
AI summary
An adversarial image generation method, a computer device, and a computer-readable storage medium are provided. The method includes the following. A reference model classification-equivalent with a target classification model is generated according to the target classification model. A target image is obtained and an original noise for the target image is generated according to the reference model. A first noise and the original noise are input into an adversarial model and a second noise corresponding to the first noise is output when the adversarial model meets a convergence condition, where the second noise enhances an information entropy of the original noise. An enhanced noise image corresponding to the target image is generated according to the second noise and the target image, where a classification accuracy of the enhanced noise image in the target classification model is less than a classification accuracy of the target image in the target classification model.


