{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T02:56:08Z","timestamp":1760151368797,"version":"build-2065373602"},"reference-count":35,"publisher":"MDPI AG","issue":"3","license":[{"start":{"date-parts":[[2022,3,12]],"date-time":"2022-03-12T00:00:00Z","timestamp":1647043200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Entropy"],"abstract":"<jats:p>Deep neural networks in the area of information security are facing a severe threat from adversarial examples (AEs). Existing methods of AE generation use two optimization models: (1) taking the successful attack as the objective function and limiting perturbations as the constraint; (2) taking the minimum of adversarial perturbations as the target and the successful attack as the constraint. These all involve two fundamental problems of AEs: the minimum boundary of constructing the AEs and whether that boundary is reachable. The reachability means whether the AEs of successful attack models exist equal to that boundary. Previous optimization models have no complete answer to the problems. Therefore, in this paper, for the first problem, we propose the definition of the minimum AEs and give the theoretical lower bound of the amplitude of the minimum AEs. For the second problem, we prove that solving the generation of the minimum AEs is an NPC problem, and then based on its computational inaccessibility, we establish a new third optimization model. This model is general and can adapt to any constraint. To verify the model, we devise two specific methods for generating controllable AEs under the widely used distance evaluation standard of adversarial perturbations, namely Lp constraint and SSIM constraint (structural similarity). This model limits the amplitude of the AEs, reduces the solution space\u2019s search cost, and is further improved in efficiency. In theory, those AEs generated by the new model which are closer to the actual minimum adversarial boundary overcome the blindness of the adversarial amplitude setting of the existing methods and further improve the attack success rate. In addition, this model can generate accurate AEs with controllable amplitude under different constraints, which is suitable for different application scenarios. In addition, through extensive experiments, they demonstrate a better attack ability under the same constraints as other baseline attacks. For all the datasets we test in the experiment, compared with other baseline methods, the attack success rate of our method is improved by approximately 10%.<\/jats:p>","DOI":"10.3390\/e24030396","type":"journal-article","created":{"date-parts":[[2022,3,13]],"date-time":"2022-03-13T22:29:43Z","timestamp":1647210583000},"page":"396","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["Minimum Adversarial Examples"],"prefix":"10.3390","volume":"24","author":[{"given":"Zhenyu","family":"Du","sequence":"first","affiliation":[{"name":"College of Electronic Engineering, National University of Defense Technology, Hefei 230037, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Fangzheng","family":"Liu","sequence":"additional","affiliation":[{"name":"College of Electronic Engineering, National University of Defense Technology, Hefei 230037, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xuehu","family":"Yan","sequence":"additional","affiliation":[{"name":"College of Electronic Engineering, National University of Defense Technology, Hefei 230037, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2022,3,12]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Eykholt, K., Evtimov, I., Fernandes, E., Li, B., Rahmati, A., Xiao, C., Prakash, A., Kohno, T., and Song, D. (2017). Robust Physical-World Attacks on Deep Learning Models. arXiv.","DOI":"10.1109\/CVPR.2018.00175"},{"key":"ref_2","first-page":"395","article-title":"Bias-Based Universal Adversarial Patch Attack for Automatic Check-Out","volume":"12358","author":"Liu","year":"2020","journal-title":"ECCV"},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Bontrager, P., Roy, A., Togelius, J., Memon, N., and Ross, A. (2018, January 22\u201325). DeepMasterPrints: Generating masterprints for dictionary attacks via latent variable evolution. Proceedings of the 2018 IEEE 9th International Conference on Biometrics Theory, Applications and Systems, BTAS 2018, Redondo Beach, CA, USA.","DOI":"10.1109\/BTAS.2018.8698539"},{"key":"ref_4","unstructured":"Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., and Fergus, R. (2013). Intriguing properties of neural networks. arXiv."},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Carlini, N., and Wagner, D. (2016, January 22\u201326). Towards Evaluating the Robustness of Neural Networks. Proceedings of the IEEE Symposium on Security and Privacy, San Jose, CA, USA.","DOI":"10.1109\/SP.2017.49"},{"key":"ref_6","unstructured":"Moosavi-Dezfooli, S.M.M., Fawzi, A., and Frossard, P. (July, January 26). DeepFool: A simple and accurate method to fool deep neural networks. Proceedings of the IEEE Computer Society Conference on Computer Vision and Pattern Recognition, Las Vegas, NV, USA."},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Carlini, N., and Wagner, D. (2017, January 3). Adversarial examples are not easily detected: Bypassing ten detection methods. Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security, Co-Located with CCS 2017, AISec 2017, Dallas, TX, USA.","DOI":"10.1145\/3128572.3140444"},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Moosavi-Dezfooli, S.M., Fawzi, A., Fawzi, O., and Frossard, P. (2017, January 21\u201326). Universal adversarial perturbations. Proceedings of the 30th IEEE Conference on Computer Vision and Pattern Recognition, CVPR 2017, Honolulu, HI, USA.","DOI":"10.1109\/CVPR.2017.17"},{"key":"ref_9","unstructured":"Athalye, A., Carlini, N., and Wagner, D. (2018, January 10\u201315). Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples. Proceedings of the 35th International Conference on Machine Learning, ICML 2018, Stockholm, Sweden."},{"key":"ref_10","first-page":"484","article-title":"Square Attack: A Query-Efficient Black-Box Adversarial Attack via Random Search","volume":"Volume 12368","author":"Andriushchenko","year":"2020","journal-title":"Lecture Notes in Computer Science (Including Subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)"},{"key":"ref_11","unstructured":"Goodfellow, I.J., Shlens, J., and Szegedy, C. (2015, January 7\u20139). Explaining and harnessing adversarial examples. Proceedings of the 3rd International Conference on Learning Representations, ICLR 2015, Conference Track Proceedings, San Diego, CA, USA."},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Papernot, N., Mcdaniel, P., Jha, S., Fredrikson, M., Celik, Z.B., and Swami, A. (2016, January 21\u201324). The limitations of deep learning in adversarial settings. Proceedings of the 2016 IEEE European Symposium on Security and Privacy, EURO S and P 2016, Hong Kong, China.","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref_13","unstructured":"Kurakin, A., Goodfellow, I.J., and Bengio, S. (2017, January 24\u201326). Adversarial examples in the physical world. Proceedings of the 5th International Conference on Learning Representations, ICLR 2017 - Workshop Track Proceedings, Toulon, France."},{"key":"ref_14","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A. (2017). Towards Deep Learning Models Resistant to Adversarial Attacks. arXiv."},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"828","DOI":"10.1109\/TEVC.2019.2890858","article-title":"One Pixel Attack for Fooling Deep Neural Networks","volume":"23","author":"Su","year":"2019","journal-title":"IEEE Trans. Evol. Comput."},{"key":"ref_16","unstructured":"Hameed, M.Z., and Gyorgy, A. (2021). Perceptually Constrained Adversarial Attacks. arXiv."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"600","DOI":"10.1109\/TIP.2003.819861","article-title":"Image quality assessment: From error visibility to structural similarity","volume":"13","author":"Wang","year":"2004","journal-title":"IEEE Trans. Image Process."},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"142","DOI":"10.1016\/j.patrec.2021.03.033","article-title":"Perceptual quality-preserving black-box attack against deep learning image classifiers","volume":"147","author":"Gragnaniello","year":"2021","journal-title":"Pattern Recognit. Lett."},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Zhao, Z., Liu, Z., and Larson, M. (2020, January 14\u201319). Towards Large Yet Imperceptible Adversarial Image Perturbations with Perceptual Color Distance. Proceedings of the IEEE Computer Society Conference on Computer Vision and Pattern Recognition, Seattle, WA, USA.","DOI":"10.1109\/CVPR42600.2020.00112"},{"key":"ref_20","unstructured":"Weng, T.W., Zhang, H., Chen, P.Y., Yi, J., Su, D., Gao, Y., Hsieh, C.J., and Daniel, L. (May, January 30). Evaluating the Robustness of Neural Networks: An Extreme Value Theory Approach. Proceedings of the 6th International Conference on Learning Representations ICLR, Vancouver, BC, Canada."},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Weng, T.w., Zhang, H., Chen, P.y., Lozano, A., Hsieh, C.j., and Daniel, L. (2018). On Extensions of CLEVER: A Neural Network Robustness Evaluation Algorithm. arXiv.","DOI":"10.1109\/GlobalSIP.2018.8646356"},{"key":"ref_22","unstructured":"Weng, T.W., Zhang, H., Chen, H., Song, Z., Hsieh, C.J., Boning, D., Dhillon, I.S., and Daniel, L. (2018). Towards fast computation of certified robustness for relu networks. arXiv."},{"key":"ref_23","unstructured":"Zhang, H., Weng, T.w., Chen, P.y., Hsieh, C.j., and Daniel, L. (2018). Efficient Neural Network Robustness Certification with General Activation Function. arXiv."},{"key":"ref_24","unstructured":"Boopathy, A., Weng, T.W., Chen, P.Y., Liu, S., and Daniel, L. (February, January 27). CNN-Cert: An efficient framework for certifying robustness of convolutional neural networks. Proceedings of the the Thirty-Third AAAI Conference on Artificial Intelligence (AAAI-19), Honolulu, HI, USA."},{"key":"ref_25","unstructured":"Sinha, A., Namkoong, H., and Duchi, J. (May, January 30). Certifying some distributional robustness with principled adversarial training. Proceedings of the 6th International Conference on Learning Representations, ICLR 2018\u2014Conference Track Proceedings, Vancouver, BC, Canada."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"455","DOI":"10.1137\/07070111X","article-title":"Tensor decompositions and applications","volume":"51","author":"Kolda","year":"2009","journal-title":"SIAM Rev."},{"key":"ref_27","unstructured":"Eykholt, K., Evtimov, I., Fernandes, E., Li, B., Rahmati, A., Tram\u00e8r, F., Prakash, A., Kohno, T., and Song, D. (2018, January 13\u201314). Physical adversarial examples for object detectors. Proceedings of the 12th USENIX Workshop on Offensive Technologies, WOOT 2018, co-located with USENIX Security 2018, Baltimore, MD, USA."},{"key":"ref_28","unstructured":"Haykin, S., and Kosko, B. (2010). GradientBased Learning Applied to Document Recognition. Intell. Signal Process., 306\u2013351."},{"key":"ref_29","unstructured":"(2022, January 20). CIFAR-10\u2014Object Recognition in Images@Kaggle. Available online: https:\/\/www.kaggle.com\/c\/cifar-10."},{"key":"ref_30","unstructured":"Simonyan, K., and Zisserman, A. (2015, January 7\u20139). Very deep convolutional networks for large-scale image recognition. Proceedings of the 3rd International Conference on Learning Representations, ICLR 2015 - Conference Track Proceedings, San Diego, CA, USA."},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"90","DOI":"10.1109\/T-C.1974.223784","article-title":"Discrete Cosine Transform","volume":"C-23","author":"Ahmed","year":"1974","journal-title":"IEEE Trans. Comput."},{"key":"ref_32","unstructured":"Krizhevsky, A. (2009). Learning Multiple Layers of Features from Tiny Images, Science Department, University of Toronto."},{"key":"ref_33","unstructured":"Kurakin, A., Goodfellow, I.J., and Bengio, S. (2017, January 24\u201326). Adversarial machine learning at scale. Proceedings of the 5th International Conference on Learning Representations, ICLR 2017- Conference Track Proceedings, Toulon, France."},{"key":"ref_34","unstructured":"Xu, K., Shi, Z., Zhang, H., Wang, Y., Chang, K.W., Huang, M., Kailkhura, B., Lin, X., and Hsieh, C.J. (2020, January 6\u201312). Automatic perturbation analysis for scalable certified robustness and beyond. Proceedings of the 34th Conference on Neural Information Processing Systems (NeurIPS 2020), Vancouver, BC, Canada."},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"1488","DOI":"10.1109\/TIP.2011.2173206","article-title":"On the mathematical properties of the structural similarity index","volume":"21","author":"Brunet","year":"2012","journal-title":"IEEE Trans. Image Process."}],"container-title":["Entropy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1099-4300\/24\/3\/396\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T22:35:29Z","timestamp":1760135729000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1099-4300\/24\/3\/396"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,3,12]]},"references-count":35,"journal-issue":{"issue":"3","published-online":{"date-parts":[[2022,3]]}},"alternative-id":["e24030396"],"URL":"https:\/\/doi.org\/10.3390\/e24030396","relation":{},"ISSN":["1099-4300"],"issn-type":[{"type":"electronic","value":"1099-4300"}],"subject":[],"published":{"date-parts":[[2022,3,12]]}}}