-
Enhancing Output Diversity Improves Conjugate Gradient-based Adversarial Attacks
Authors:
Keiichiro Yamamura,
Issa Oe,
Hiroki Ishikura,
Katsuki Fujisawa
Abstract:
Deep neural networks are vulnerable to adversarial examples, and adversarial attacks that generate adversarial examples have been studied in this context. Existing studies imply that increasing the diversity of model outputs contributes to improving the attack performance. This study focuses on the Auto Conjugate Gradient (ACG) attack, which is inspired by the conjugate gradient method and has a h…
▽ More
Deep neural networks are vulnerable to adversarial examples, and adversarial attacks that generate adversarial examples have been studied in this context. Existing studies imply that increasing the diversity of model outputs contributes to improving the attack performance. This study focuses on the Auto Conjugate Gradient (ACG) attack, which is inspired by the conjugate gradient method and has a high diversification performance. We hypothesized that increasing the distance between two consecutive search points would enhance the output diversity. To test our hypothesis, we propose Rescaling-ACG (ReACG), which automatically modifies the two components that significantly affect the distance between two consecutive search points, including the search direction and step size. ReACG showed higher attack performance than that of ACG, and is particularly effective for ImageNet models with several classification classes. Experimental results show that the distance between two consecutive search points enhances the output diversity and may help develop new potent attacks. The code is available at \url{https://github.com/yamamura-k/ReACG}
△ Less
Submitted 7 August, 2024;
originally announced August 2024.
-
Diversified Adversarial Attacks based on Conjugate Gradient Method
Authors:
Keiichiro Yamamura,
Haruki Sato,
Nariaki Tateiwa,
Nozomi Hata,
Toru Mitsutake,
Issa Oe,
Hiroki Ishikura,
Katsuki Fujisawa
Abstract:
Deep learning models are vulnerable to adversarial examples, and adversarial attacks used to generate such examples have attracted considerable research interest. Although existing methods based on the steepest descent have achieved high attack success rates, ill-conditioned problems occasionally reduce their performance. To address this limitation, we utilize the conjugate gradient (CG) method, w…
▽ More
Deep learning models are vulnerable to adversarial examples, and adversarial attacks used to generate such examples have attracted considerable research interest. Although existing methods based on the steepest descent have achieved high attack success rates, ill-conditioned problems occasionally reduce their performance. To address this limitation, we utilize the conjugate gradient (CG) method, which is effective for this type of problem, and propose a novel attack algorithm inspired by the CG method, named the Auto Conjugate Gradient (ACG) attack. The results of large-scale evaluation experiments conducted on the latest robust models show that, for most models, ACG was able to find more adversarial examples with fewer iterations than the existing SOTA algorithm Auto-PGD (APGD). We investigated the difference in search performance between ACG and APGD in terms of diversification and intensification, and define a measure called Diversity Index (DI) to quantify the degree of diversity. From the analysis of the diversity using this index, we show that the more diverse search of the proposed method remarkably improves its attack success rate.
△ Less
Submitted 19 July, 2022; v1 submitted 20 June, 2022;
originally announced June 2022.
-
Long-Term Optimal Delivery Planning for Replacing the Liquefied Petroleum Gas Cylinder
Authors:
Akihiro Yoshida,
Haruki Sato,
Shiori Uchiumi,
Nariaki Tateiwa,
Daisuke Kataoka,
Akira Tanaka,
Nozomi Hata,
Yousuke Yatsushiro,
Ayano Ide,
Hiroki Ishikura,
Shingo Egi,
Miyu Fujii,
Hiroki Kai,
Katsuki Fujisawa
Abstract:
In the daily operation of liquefied petroleum gas service, gas providers visit customers and replace cylinders if the gas is about to run out. For a long time, frequent visits to customers were required because they could not determine the amount of remaining gas without a staff visit and observation. To solve this problem, smart meters are started to be employed to acquire gas consumption more fr…
▽ More
In the daily operation of liquefied petroleum gas service, gas providers visit customers and replace cylinders if the gas is about to run out. For a long time, frequent visits to customers were required because they could not determine the amount of remaining gas without a staff visit and observation. To solve this problem, smart meters are started to be employed to acquire gas consumption more frequently without visiting customers. In this study, we construct a system to optimize plans for cylinder replacement, and evaluate it with a large-scale field test. We propose an algorithm to create a replacement plan with three steps: estimating the replacement date, acquiring the customer list for replacement, and determining the delivery route. A more accurate estimation of the replacement date can be acquired with a smart meter, which is used for making a customer list for replacement. The formulation for making a customer list enables the gas provider to replace cylinders some days before the date when the gas would run out. It can suppress the concentration of replacements on certain days. Large-scale verification experiments were performed with more than 1,000 customers in Chiba prefecture in Japan. In the field test, the gas provider incorporated the system into its replacement operations. Moreover, the replacement plans developed by the proposed system were compared with that by the gas provider. Our system reduced the number of gas cylinders with gas shortage, the number of visits without replacement due to plenty of gas remaining, and the working duration per customer, which shows that our system benefits both gas providers and customers.
△ Less
Submitted 20 June, 2022; v1 submitted 22 December, 2021;
originally announced December 2021.