GMM: Efficient information-containing adversarial perturbation based on gradient masking method.

Saved in:
Bibliographic Details
Title: GMM: Efficient information-containing adversarial perturbation based on gradient masking method.
Authors: Lin, Hanbin1,2 (AUTHOR), Liao, Wenxing2 (AUTHOR), Shu, Zhaogang2 (AUTHOR), Liu, Xiaolong1,2,3 (AUTHOR) xlliu@fafu.edu.cn
Source: Information Fusion. Mar2026:Part B, Vol. 127, pN.PAG-N.PAG. 1p.
Subjects: Artificial neural networks, Digital watermarking, Information processing, Perturbation theory
Abstract: • An efficient adversarial attack scheme with meaningful perturbation is proposed based on gradient masking. • The proposed method outperformed other baseline methods in fooling deep neural network models in experimental scenarios. • The generated adversarial examples exhibit dual functionality, retaining their adversarial properties while embedding the information within the host image. Adversarial examples have been a significant research focus since their discovery. Recent studies have applied watermarking and data hiding techniques to generate meaningful adversarial perturbations that carry specific information, further enriching the functionality of adversarial examples. However, these methods struggle to balance time complexity with attack efficacy. To address this issue, we propose the Gradient Masking Method (GMM), introducing a new perspective on generating meaningful perturbations. Unlike previous techniques that directly embed watermarks or data as adversarial distortions, GMM embeds information into adversarial perturbations by selectively blocking the updating noise at specific positions using a message mask encoded from the information. The resulting perturbations represent the binary sequence of the embedded message. This method enables processed images to exhibit adversarial properties while simultaneously serving as carriers of information. Experimental results demonstrate the efficacy of our approach. In terms of computational cost, our method significantly outperforms previous techniques without compromising attack effectiveness. We evaluated the attack success rate of the proposed method across seven widely used classifier models, comparing it with baseline and black-box attack methods. Results confirm that our method performs effectively in common attack scenarios influenced by the message mask. The code of GMM can be found at https://github.com/Abin110/Gradient-Masking_. [ABSTRACT FROM AUTHOR]
Copyright of Information Fusion is the property of Elsevier B.V. and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.)
Database: Engineering Source
FullText Text:
  Availability: 0
Header DbId: egs
DbLabel: Engineering Source
An: 189339044
AccessLevel: 6
PubType: Academic Journal
PubTypeId: academicJournal
PreciseRelevancyScore: 0
IllustrationInfo
Items – Name: Title
  Label: Title
  Group: Ti
  Data: GMM: Efficient information-containing adversarial perturbation based on gradient masking method.
– Name: Author
  Label: Authors
  Group: Au
  Data: <searchLink fieldCode="AR" term="%22Lin%2C+Hanbin%22">Lin, Hanbin</searchLink><relatesTo>1,2</relatesTo> (AUTHOR)<br /><searchLink fieldCode="AR" term="%22Liao%2C+Wenxing%22">Liao, Wenxing</searchLink><relatesTo>2</relatesTo> (AUTHOR)<br /><searchLink fieldCode="AR" term="%22Shu%2C+Zhaogang%22">Shu, Zhaogang</searchLink><relatesTo>2</relatesTo> (AUTHOR)<br /><searchLink fieldCode="AR" term="%22Liu%2C+Xiaolong%22">Liu, Xiaolong</searchLink><relatesTo>1,2,3</relatesTo> (AUTHOR)<i> xlliu@fafu.edu.cn</i>
– Name: TitleSource
  Label: Source
  Group: Src
  Data: <searchLink fieldCode="JN" term="%22Information+Fusion%22">Information Fusion</searchLink>. Mar2026:Part B, Vol. 127, pN.PAG-N.PAG. 1p.
– Name: Subject
  Label: Subjects
  Group: Su
  Data: <searchLink fieldCode="DE" term="%22Artificial+neural+networks%22">Artificial neural networks</searchLink><br /><searchLink fieldCode="DE" term="%22Digital+watermarking%22">Digital watermarking</searchLink><br /><searchLink fieldCode="DE" term="%22Information+processing%22">Information processing</searchLink><br /><searchLink fieldCode="DE" term="%22Perturbation+theory%22">Perturbation theory</searchLink>
– Name: Abstract
  Label: Abstract
  Group: Ab
  Data: • An efficient adversarial attack scheme with meaningful perturbation is proposed based on gradient masking. • The proposed method outperformed other baseline methods in fooling deep neural network models in experimental scenarios. • The generated adversarial examples exhibit dual functionality, retaining their adversarial properties while embedding the information within the host image. Adversarial examples have been a significant research focus since their discovery. Recent studies have applied watermarking and data hiding techniques to generate meaningful adversarial perturbations that carry specific information, further enriching the functionality of adversarial examples. However, these methods struggle to balance time complexity with attack efficacy. To address this issue, we propose the Gradient Masking Method (GMM), introducing a new perspective on generating meaningful perturbations. Unlike previous techniques that directly embed watermarks or data as adversarial distortions, GMM embeds information into adversarial perturbations by selectively blocking the updating noise at specific positions using a message mask encoded from the information. The resulting perturbations represent the binary sequence of the embedded message. This method enables processed images to exhibit adversarial properties while simultaneously serving as carriers of information. Experimental results demonstrate the efficacy of our approach. In terms of computational cost, our method significantly outperforms previous techniques without compromising attack effectiveness. We evaluated the attack success rate of the proposed method across seven widely used classifier models, comparing it with baseline and black-box attack methods. Results confirm that our method performs effectively in common attack scenarios influenced by the message mask. The code of GMM can be found at https://github.com/Abin110/Gradient-Masking_. [ABSTRACT FROM AUTHOR]
– Name: AbstractSuppliedCopyright
  Label:
  Group: Ab
  Data: <i>Copyright of Information Fusion is the property of Elsevier B.V. and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract.</i> (Copyright applies to all Abstracts.)
PLink https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=egs&AN=189339044
RecordInfo BibRecord:
  BibEntity:
    Identifiers:
      – Type: doi
        Value: 10.1016/j.inffus.2025.103864
    Languages:
      – Code: eng
        Text: English
    PhysicalDescription:
      Pagination:
        PageCount: 1
        StartPage: N.PAG
    Subjects:
      – SubjectFull: Artificial neural networks
        Type: general
      – SubjectFull: Digital watermarking
        Type: general
      – SubjectFull: Information processing
        Type: general
      – SubjectFull: Perturbation theory
        Type: general
    Titles:
      – TitleFull: GMM: Efficient information-containing adversarial perturbation based on gradient masking method.
        Type: main
  BibRelationships:
    HasContributorRelationships:
      – PersonEntity:
          Name:
            NameFull: Lin, Hanbin
      – PersonEntity:
          Name:
            NameFull: Liao, Wenxing
      – PersonEntity:
          Name:
            NameFull: Shu, Zhaogang
      – PersonEntity:
          Name:
            NameFull: Liu, Xiaolong
    IsPartOfRelationships:
      – BibEntity:
          Dates:
            – D: 05
              M: 03
              Text: Mar2026:Part B
              Type: published
              Y: 2026
          Identifiers:
            – Type: issn-print
              Value: 15662535
          Numbering:
            – Type: volume
              Value: 127
          Titles:
            – TitleFull: Information Fusion
              Type: main
ResultId 1