MULTI-LABEL ADVERSARIAL ATTACK BASED ON LABEL CORRELATION
Mingzhi Ma, Weijie Zheng, Wanli Lv, Lu Ren, Hang Su, Zhaoxia Yin
-
SPS
IEEE Members: $11.00
Non-members: $15.00
The vulnerabilities of multi-label models concerning adversarial attacks have been paid much attention. In the multi-label model, the labels are not independent of each other. However, the existing multi-label adversarial attack works do not adequately consider label correlations, thus unable to cost the most minor disturbance while ensuring the attack success rate. To address this issue, we develop a method that uses the label correlation. For targeted attacks, we build a label correlation matrix using cosine distance and select the label with the highest correlation score with the attacked label as the target label. For untargeted attacks, we choose the attacked label with the lowest confidence because of the label correlation. The proposed method can achieve low attack costs with high success rates, as demonstrated in experimental results.