GMM: Efficient information-containing adversarial perturbation based on gradient masking method.
Saved in:
| Title: | GMM: Efficient information-containing adversarial perturbation based on gradient masking method. |
|---|---|
| Authors: | Lin, Hanbin1,2 (AUTHOR), Liao, Wenxing2 (AUTHOR), Shu, Zhaogang2 (AUTHOR), Liu, Xiaolong1,2,3 (AUTHOR) xlliu@fafu.edu.cn |
| Source: | Information Fusion. Mar2026:Part B, Vol. 127, pN.PAG-N.PAG. 1p. |
| Subjects: | Artificial neural networks, Digital watermarking, Information processing, Perturbation theory |
| Abstract: | • An efficient adversarial attack scheme with meaningful perturbation is proposed based on gradient masking. • The proposed method outperformed other baseline methods in fooling deep neural network models in experimental scenarios. • The generated adversarial examples exhibit dual functionality, retaining their adversarial properties while embedding the information within the host image. Adversarial examples have been a significant research focus since their discovery. Recent studies have applied watermarking and data hiding techniques to generate meaningful adversarial perturbations that carry specific information, further enriching the functionality of adversarial examples. However, these methods struggle to balance time complexity with attack efficacy. To address this issue, we propose the Gradient Masking Method (GMM), introducing a new perspective on generating meaningful perturbations. Unlike previous techniques that directly embed watermarks or data as adversarial distortions, GMM embeds information into adversarial perturbations by selectively blocking the updating noise at specific positions using a message mask encoded from the information. The resulting perturbations represent the binary sequence of the embedded message. This method enables processed images to exhibit adversarial properties while simultaneously serving as carriers of information. Experimental results demonstrate the efficacy of our approach. In terms of computational cost, our method significantly outperforms previous techniques without compromising attack effectiveness. We evaluated the attack success rate of the proposed method across seven widely used classifier models, comparing it with baseline and black-box attack methods. Results confirm that our method performs effectively in common attack scenarios influenced by the message mask. The code of GMM can be found at https://github.com/Abin110/Gradient-Masking_. [ABSTRACT FROM AUTHOR] |
| Copyright of Information Fusion is the property of Elsevier B.V. and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.) | |
| Database: | Engineering Source |
Be the first to leave a comment!