A gradient-based algorithm to deceive deep neural networks

4Citations
Citations of this article
3Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Deep neural networks have achieved high performance in a variety of image recognition tasks. However, it is reported that the performance on image recognition of these networks is unstable to slight perturbations of images. To verify this weakness, we propose DeceiveDeep, a gradient-based algorithm for deceiving deep neural networks in this paper. There exists a lot of gradient-based attack methods, such as the L-BFGS, FGSM, and Deepfool. Specifically, based on an original method, L-BFGS, we exploit the Euclid norm of the gradient to update the space vector in an image to generate a deceivable image for fooling deep neural networks. We construct three types of deep neural network models and one convolutional neural network for testing the proposed algorithm. Based on the MNIST dataset and the Fashion-MNIST dataset, we evaluate the effectiveness of DeceiveDeep in terms of accuracy on training and testing data, and CNN model, respectively. The experimental results show that, comparing with L-BFGS, DeceiveDeep dramatically decreases the accuracy of the deep models on image recognition.

Cite

CITATION STYLE

APA

Xie, T., & Li, Y. (2019). A gradient-based algorithm to deceive deep neural networks. In Communications in Computer and Information Science (Vol. 1142 CCIS, pp. 57–65). Springer. https://doi.org/10.1007/978-3-030-36808-1_7

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free