Simultaneously Optimizing Perturbations and Positions for Black-Box Adversarial Patch Attacks

Adversarial patch is an important form of real-world adversarial attack that brings serious risks to the robustness of deep neural networks. Previous methods generate adversarial patches by either optimizing their perturbation values while fixing the pasting position or manipulating the position whi...

Ausführliche Beschreibung

Bibliographische Detailangaben
Veröffentlicht in:IEEE transactions on pattern analysis and machine intelligence. - 1979. - 45(2023), 7 vom: 26. Juli, Seite 9041-9054
1. Verfasser: Wei, Xingxing (VerfasserIn)
Weitere Verfasser: Guo, Ying, Yu, Jie, Zhang, Bo
Format: Online-Aufsatz
Sprache:English
Veröffentlicht: 2023
Zugriff auf das übergeordnete Werk:IEEE transactions on pattern analysis and machine intelligence
Schlagworte:Journal Article