Masked projected gradient transfer attacks

    公开(公告)号:US11948054B2

    公开(公告)日:2024-04-02

    申请号:US17083928

    申请日:2020-10-29

    CPC classification number: G06N20/00 H04L63/1416 H04L63/1466

    Abstract: A system and method for transferring an adversarial attack involving generating a surrogate model having an architecture and a dataset that mirrors at least one aspect of a target model of a target module, wherein the surrogate model includes a plurality of classes. The method involves generating a masked version of the surrogate model having fewer classes than the surrogate model by randomly selecting at least one class of the plurality of classes for removal. The method involves attacking the masked surrogate model to create a perturbed sample. The method involves generalizing the perturbed sample for use with the target module. The method involves transferring the perturbed sample to the target module to alter an operating parameter of the target model.

Patent Agency Ranking