Abstract—Researchers have found that we artificially add perturbation to the input image to generate adversarial examples which can cause the deep learning model to misclassify. The existing method of generating adversarial examples can achieve high white-box attack success rate, but the one of black-box attack is low. In order to improve the transferability ability of adversarial examples and obtain higher attack success rate, we apply the Nesterov momentum optimization method to the gradient-based adversarial examples generation method. Combined with the momentum and decay factor, the iterative gradient is optimized during the optimization process. This effectively escapes the local minima during the optimization process, resulting in faster iterations and better adversarial examples generation. The experiment showed that the white-box attack achieves 100% attack success rate, and the powerful transferability of the examples make the black-box attack success rate significantly higher than the original methods.
Index Terms—Adversarial examples, attack success rate, powerful transferability, nesterov momentum optimization method.
The authors are with the Department of Computer Science, Nanjing University of Posts and Telecommunications, China (e-mail: email@example.com, firstname.lastname@example.org, email@example.com).
Cite: Yunfang Chen, Qiangchun Liu, and Wei Zhang, "A Powerful Transferability Adversarial Examples Generation Method Based on Nesterov Momentum Optimization," International Journal of Machine Learning and Computing vol. 10, no. 3, pp. 431-436, 2020.Copyright © 2020 by the authors. This is an open access article distributed under the Creative Commons Attribution License which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited (CC BY 4.0).