Journal of Computer Applications ›› 2023, Vol. 43 ›› Issue (11): 3428-3435.DOI: 10.11772/j.issn.1001-9081.2022111677

Special Issue: 人工智能

• Artificial intelligence • Previous Articles     Next Articles

Cross-model universal perturbation generation method based on geometric relationship

Jici ZHANG, Chunlong FAN(), Cailong LI, Xuedong ZHENG   

  1. School of Computer Science,Shenyang Aerospace University,Shenyang Liaoning 110136,China
  • Received:2022-11-11 Revised:2023-04-06 Accepted:2023-04-11 Online:2023-05-08 Published:2023-11-10
  • Contact: Chunlong FAN
  • About author:ZHANG Jici, born in 1998, M. S. candidate. Her research interests include deep learning, adversarial attack.
    FAN Chunlong, born in 1973, Ph. D., professor. His research interests include neural network interpretability, complex network analysis, intelligent system validation.
    LI Cailong, born in 1997, M. S. candidate. His research interests include deep learning, adversarial attack.
    ZHENG Xuedong, born in 1977, Ph. D., professor. His research interests include DNA computing, artificial intelligence.
  • Supported by:
    National Natural Science Foundation of China(61972266)


张济慈, 范纯龙(), 李彩龙, 郑学东   

  1. 沈阳航空航天大学 计算机学院,沈阳 110136
  • 通讯作者: 范纯龙
  • 作者简介:张济慈(1998—),女,辽宁海城人,硕士研究生,CCF会员,主要研究方向:深度学习、对抗攻击
  • 基金资助:


Adversarial attacks add designed perturbations to the input samples of neural network models to make them output wrong results with high confidence. The research on adversarial attacks mainly aim at the application scenarios of a single model, and the attacks on multiple models are mainly realized through cross-model transfer attacks, but there are few studies on universal cross-model attack methods. By analyzing the geometric relationship of multi-model attack perturbations, the orthogonality of the adversarial directions of different models and the orthogonality of the adversarial direction and the decision boundary of a single model were clarified, and the universal cross-model attack algorithm and corresponding optimization strategy were designed accordingly. On CIFAR10, SVHN datasets and six common neural network models, the proposed algorithm was verified by multi-angle cross-model adversarial attacks. Experimental results show that the attack success rate of the algorithm in a given experimental scenario is 1.0, and the L2-norm is not greater than 0.9. Compared with the cross-model transfer attack, the proposed algorithm has the average attack success rate on the six models increased by up to 57% and has better universality.

Key words: deep learning, adversarial sample generation, adversarial attack, cross-model attack, classifier



关键词: 深度学习, 对抗样本生成, 对抗攻击, 跨模型攻击, 分类器

CLC Number: