GMM: Efficient information-containing adversarial perturbation based on gradient masking method.
Saved in:
| Title: | GMM: Efficient information-containing adversarial perturbation based on gradient masking method. |
|---|---|
| Authors: | Lin, Hanbin1,2 (AUTHOR), Liao, Wenxing2 (AUTHOR), Shu, Zhaogang2 (AUTHOR), Liu, Xiaolong1,2,3 (AUTHOR) xlliu@fafu.edu.cn |
| Source: | Information Fusion. Mar2026:Part B, Vol. 127, pN.PAG-N.PAG. 1p. |
| Subjects: | Artificial neural networks, Digital watermarking, Information processing, Perturbation theory |
| Abstract: | • An efficient adversarial attack scheme with meaningful perturbation is proposed based on gradient masking. • The proposed method outperformed other baseline methods in fooling deep neural network models in experimental scenarios. • The generated adversarial examples exhibit dual functionality, retaining their adversarial properties while embedding the information within the host image. Adversarial examples have been a significant research focus since their discovery. Recent studies have applied watermarking and data hiding techniques to generate meaningful adversarial perturbations that carry specific information, further enriching the functionality of adversarial examples. However, these methods struggle to balance time complexity with attack efficacy. To address this issue, we propose the Gradient Masking Method (GMM), introducing a new perspective on generating meaningful perturbations. Unlike previous techniques that directly embed watermarks or data as adversarial distortions, GMM embeds information into adversarial perturbations by selectively blocking the updating noise at specific positions using a message mask encoded from the information. The resulting perturbations represent the binary sequence of the embedded message. This method enables processed images to exhibit adversarial properties while simultaneously serving as carriers of information. Experimental results demonstrate the efficacy of our approach. In terms of computational cost, our method significantly outperforms previous techniques without compromising attack effectiveness. We evaluated the attack success rate of the proposed method across seven widely used classifier models, comparing it with baseline and black-box attack methods. Results confirm that our method performs effectively in common attack scenarios influenced by the message mask. The code of GMM can be found at https://github.com/Abin110/Gradient-Masking_. [ABSTRACT FROM AUTHOR] |
| Copyright of Information Fusion is the property of Elsevier B.V. and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.) | |
| Database: | Engineering Source |
| FullText | Text: Availability: 0 |
|---|---|
| Header | DbId: egs DbLabel: Engineering Source An: 189339044 AccessLevel: 6 PubType: Academic Journal PubTypeId: academicJournal PreciseRelevancyScore: 0 |
| IllustrationInfo | |
| Items | – Name: Title Label: Title Group: Ti Data: GMM: Efficient information-containing adversarial perturbation based on gradient masking method. – Name: Author Label: Authors Group: Au Data: <searchLink fieldCode="AR" term="%22Lin%2C+Hanbin%22">Lin, Hanbin</searchLink><relatesTo>1,2</relatesTo> (AUTHOR)<br /><searchLink fieldCode="AR" term="%22Liao%2C+Wenxing%22">Liao, Wenxing</searchLink><relatesTo>2</relatesTo> (AUTHOR)<br /><searchLink fieldCode="AR" term="%22Shu%2C+Zhaogang%22">Shu, Zhaogang</searchLink><relatesTo>2</relatesTo> (AUTHOR)<br /><searchLink fieldCode="AR" term="%22Liu%2C+Xiaolong%22">Liu, Xiaolong</searchLink><relatesTo>1,2,3</relatesTo> (AUTHOR)<i> xlliu@fafu.edu.cn</i> – Name: TitleSource Label: Source Group: Src Data: <searchLink fieldCode="JN" term="%22Information+Fusion%22">Information Fusion</searchLink>. Mar2026:Part B, Vol. 127, pN.PAG-N.PAG. 1p. – Name: Subject Label: Subjects Group: Su Data: <searchLink fieldCode="DE" term="%22Artificial+neural+networks%22">Artificial neural networks</searchLink><br /><searchLink fieldCode="DE" term="%22Digital+watermarking%22">Digital watermarking</searchLink><br /><searchLink fieldCode="DE" term="%22Information+processing%22">Information processing</searchLink><br /><searchLink fieldCode="DE" term="%22Perturbation+theory%22">Perturbation theory</searchLink> – Name: Abstract Label: Abstract Group: Ab Data: • An efficient adversarial attack scheme with meaningful perturbation is proposed based on gradient masking. • The proposed method outperformed other baseline methods in fooling deep neural network models in experimental scenarios. • The generated adversarial examples exhibit dual functionality, retaining their adversarial properties while embedding the information within the host image. Adversarial examples have been a significant research focus since their discovery. Recent studies have applied watermarking and data hiding techniques to generate meaningful adversarial perturbations that carry specific information, further enriching the functionality of adversarial examples. However, these methods struggle to balance time complexity with attack efficacy. To address this issue, we propose the Gradient Masking Method (GMM), introducing a new perspective on generating meaningful perturbations. Unlike previous techniques that directly embed watermarks or data as adversarial distortions, GMM embeds information into adversarial perturbations by selectively blocking the updating noise at specific positions using a message mask encoded from the information. The resulting perturbations represent the binary sequence of the embedded message. This method enables processed images to exhibit adversarial properties while simultaneously serving as carriers of information. Experimental results demonstrate the efficacy of our approach. In terms of computational cost, our method significantly outperforms previous techniques without compromising attack effectiveness. We evaluated the attack success rate of the proposed method across seven widely used classifier models, comparing it with baseline and black-box attack methods. Results confirm that our method performs effectively in common attack scenarios influenced by the message mask. The code of GMM can be found at https://github.com/Abin110/Gradient-Masking_. [ABSTRACT FROM AUTHOR] – Name: AbstractSuppliedCopyright Label: Group: Ab Data: <i>Copyright of Information Fusion is the property of Elsevier B.V. and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract.</i> (Copyright applies to all Abstracts.) |
| PLink | https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=egs&AN=189339044 |
| RecordInfo | BibRecord: BibEntity: Identifiers: – Type: doi Value: 10.1016/j.inffus.2025.103864 Languages: – Code: eng Text: English PhysicalDescription: Pagination: PageCount: 1 StartPage: N.PAG Subjects: – SubjectFull: Artificial neural networks Type: general – SubjectFull: Digital watermarking Type: general – SubjectFull: Information processing Type: general – SubjectFull: Perturbation theory Type: general Titles: – TitleFull: GMM: Efficient information-containing adversarial perturbation based on gradient masking method. Type: main BibRelationships: HasContributorRelationships: – PersonEntity: Name: NameFull: Lin, Hanbin – PersonEntity: Name: NameFull: Liao, Wenxing – PersonEntity: Name: NameFull: Shu, Zhaogang – PersonEntity: Name: NameFull: Liu, Xiaolong IsPartOfRelationships: – BibEntity: Dates: – D: 05 M: 03 Text: Mar2026:Part B Type: published Y: 2026 Identifiers: – Type: issn-print Value: 15662535 Numbering: – Type: volume Value: 127 Titles: – TitleFull: Information Fusion Type: main |
| ResultId | 1 |