{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,10]],"date-time":"2026-05-10T10:14:03Z","timestamp":1778408043605,"version":"3.51.4"},"reference-count":28,"publisher":"MDPI AG","issue":"12","license":[{"start":{"date-parts":[[2018,12,10]],"date-time":"2018-12-10T00:00:00Z","timestamp":1544400000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100003725","name":"National Research Foundation of Korea","doi-asserted-by":"publisher","award":["2016R1A4A1011761"],"award-info":[{"award-number":["2016R1A4A1011761"]}],"id":[{"id":"10.13039\/501100003725","id-type":"DOI","asserted-by":"publisher"}]},{"name":"National Research Foundation  of Korea","award":["2017R1A2B4006026"],"award-info":[{"award-number":["2017R1A2B4006026"]}]},{"DOI":"10.13039\/501100010418","name":"Institute for Information and communications Technology Promotion","doi-asserted-by":"publisher","award":["2016-0-00173"],"award-info":[{"award-number":["2016-0-00173"]}],"id":[{"id":"10.13039\/501100010418","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Symmetry"],"abstract":"<jats:p>Deep neural networks (DNNs) have demonstrated remarkable performance in machine learning areas such as image recognition, speech recognition, intrusion detection, and pattern analysis. However, it has been revealed that DNNs have weaknesses in the face of adversarial examples, which are created by adding a little noise to an original sample to cause misclassification by the DNN. Such adversarial examples can lead to fatal accidents in applications such as autonomous vehicles and disease diagnostics. Thus, the generation of adversarial examples has attracted extensive research attention recently. An adversarial example is categorized as targeted or untargeted. In this paper, we focus on the untargeted adversarial example scenario because it has a faster learning time and less distortion compared with the targeted adversarial example. However, there is a pattern vulnerability with untargeted adversarial examples: Because of the similarity between the original class and certain specific classes, it may be possible for the defending system to determine the original class by analyzing the output classes of the untargeted adversarial examples. To overcome this problem, we propose a new method for generating untargeted adversarial examples, one that uses an arbitrary class in the generation process. Moreover, we show that our proposed scheme can be applied to steganography. Through experiments, we show that our proposed scheme can achieve a 100% attack success rate with minimum distortion (1.99 and 42.32 using the MNIST and CIFAR10 datasets, respectively) and without the pattern vulnerability. Using a steganography test, we show that our proposed scheme can be used to fool humans, as demonstrated by the probability of their detecting hidden classes being equal to that of random selection.<\/jats:p>","DOI":"10.3390\/sym10120738","type":"journal-article","created":{"date-parts":[[2018,12,10]],"date-time":"2018-12-10T11:31:16Z","timestamp":1544441476000},"page":"738","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":22,"title":["Random Untargeted Adversarial Example on Deep Neural Network"],"prefix":"10.3390","volume":"10","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1169-9892","authenticated-orcid":false,"given":"Hyun","family":"Kwon","sequence":"first","affiliation":[{"name":"School of Computing, Korea Advanced Institute of Science and Technology, Daejeon 34141, Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yongchul","family":"Kim","sequence":"additional","affiliation":[{"name":"Department of Electrical Engineering, Korea Military Academy, Seoul 01805, Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hyunsoo","family":"Yoon","sequence":"additional","affiliation":[{"name":"School of Computing, Korea Advanced Institute of Science and Technology, Daejeon 34141, Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Daeseon","family":"Choi","sequence":"additional","affiliation":[{"name":"Department of Medical Information, Kongju National University, Gongju-si 32588, Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2018,12,10]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"85","DOI":"10.1016\/j.neunet.2014.09.003","article-title":"Deep learning in neural networks: An overview","volume":"61","author":"Schmidhuber","year":"2015","journal-title":"Neural Netw."},{"key":"ref_2","unstructured":"Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., and Fergus, R. (2014, January 14\u201316). Intriguing properties of neural networks. Proceedings of the International Conference on Learning Representations, Banff, AB, Canada."},{"key":"ref_3","unstructured":"LeCun, Y., Cortes, C., and Burges, C.J. (2018, December 04). MNIST Handwritten Digit Database. Available online: http:\/\/yann.lecun.com\/exdb\/mnist."},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Kwon, H., Kim, Y., Yoon, H., and Choi, D. (2018, January 29\u201331). Fooling a Neural Network in Military Environments: Random Untargeted Adversarial Example. Proceedings of the Military Communications Conference, Los Angeles, CA, USA.","DOI":"10.1109\/MILCOM.2018.8599707"},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"727","DOI":"10.1016\/j.sigpro.2009.08.010","article-title":"Digital image steganography: Survey and analysis of current methods","volume":"90","author":"Cheddad","year":"2010","journal-title":"Signal Process."},{"key":"ref_6","unstructured":"Krizhevsky, A., Nair, V., and Hinton, G. (2018, December 04). The CIFAR-10 Dataset. Available online: http:\/\/www.cs.toronto.edu\/kriz\/cifar.html."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"121","DOI":"10.1007\/s10994-010-5188-5","article-title":"The security of machine learning","volume":"81","author":"Barreno","year":"2010","journal-title":"Mach. Learn."},{"key":"ref_8","unstructured":"Biggio, B., Nelson, B., and Laskov, P. (July, January 26). Poisoning attacks against support vector machines. Proceedings of the 29th International Coference on International Conference on Machine Learning, Edinburgh, UK."},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Carlini, N., and Wagner, D. (2017, January 22\u201324). Towards evaluating the robustness of neural networks. Proceedings of the 2017 IEEE Symposium on Security and Privacy (SP), San Jose, CA, USA.","DOI":"10.1109\/SP.2017.49"},{"key":"ref_10","unstructured":"Moosavi-Dezfooli, S.M., Fawzi, A., and Frossard, P. (July, January 26). Deepfool: A simple and accurate method to fool deep neural networks. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Las Vegas, NV, USA."},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Papernot, N., McDaniel, P., Goodfellow, I., Jha, S., Celik, Z.B., and Swami, A. (2017, January 2\u20136). Practical black-box attacks against machine learning. Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security, Abu Dhabi, UAE.","DOI":"10.1145\/3052973.3053009"},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"2485","DOI":"10.1587\/transinf.2018EDP7073","article-title":"Advanced Ensemble Adversarial Example on Unknown Deep Neural Network Classifiers","volume":"101","author":"Kwon","year":"2018","journal-title":"IEICE Trans. Inf. Syst."},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Meng, D., and Chen, H. (November, January 30). Magnet: A two-pronged defense against adversarial examples. Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, Dallas, TX, USA.","DOI":"10.1145\/3133956.3134057"},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Carlini, N., and Wagner, D. (2017, January 3). Adversarial examples are not easily detected: Bypassing ten detection methods. Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security, Dallas, TX, USA.","DOI":"10.1145\/3128572.3140444"},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Kwon, H., Yoon, H., and Choi, D. (2018, January 4\u20138). POSTER: Zero-Day Evasion Attack Analysis on Race between Attack and Defense. Proceedings of the 2018 on Asia Conference on Computer and Communications Security, Songdo, Incheon, Korea.","DOI":"10.1145\/3196494.3201583"},{"key":"ref_16","unstructured":"Kurakin, A., Goodfellow, I.J., and Bengio, S. (2017, January 24\u201326). Adversarial Machine Learning at Scale. Proceedings of the International Conference on Learning Representations (ICLR), Toulon, France."},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Narodytska, N., and Kasiviswanathan, S. (2017, January 21\u201326). Simple black-box adversarial attacks on deep neural networks. Proceedings of the 2017 IEEE Conference on Computer Vision and Pattern Recognition Workshops (CVPRW), Honolulu, HI, USA.","DOI":"10.1109\/CVPRW.2017.172"},{"key":"ref_18","unstructured":"Strauss, T., Hanselmann, M., Junginger, A., and Ulmer, H. (arXiv, 2017). Ensemble Methods as a Defense to Adversarial Perturbations Against Deep Neural Networks, arXiv."},{"key":"ref_19","unstructured":"Goodfellow, I., Shlens, J., and Szegedy, C. (2015, January 7\u20139). Explaining and Harnessing Adversarial Examples. Proceedings of the International Conference on Learning Representations, San Diego, CA, USA."},{"key":"ref_20","unstructured":"Kurakin, A., Goodfellow, I., and Bengio, S. (2017, January 24\u201326). Adversarial examples in the physical world. Proceedings of the ICLR Workshop, Toulon, France."},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Papernot, N., McDaniel, P., Wu, X., Jha, S., and Swami, A. (2016, January 23\u201325). Distillation as a defense to adversarial perturbations against deep neural networks. Proceedings of the 2016 IEEE Symposium on Security and Privacy (SP), San Jose, CA, USA.","DOI":"10.1109\/SP.2016.41"},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"380","DOI":"10.1016\/j.cose.2018.07.015","article-title":"Friend-safe Evasion Attack: An adversarial example that is correctly recognized by a friendly classifier","volume":"78","author":"Kwon","year":"2018","journal-title":"Comput. Secur."},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"46084","DOI":"10.1109\/ACCESS.2018.2866197","article-title":"Multi-Targeted Adversarial Example in Evasion Attack on Deep Neural Network","volume":"6","author":"Kwon","year":"2018","journal-title":"IEEE Access"},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Papernot, N., McDaniel, P., Jha, S., Fredrikson, M., Celik, Z.B., and Swami, A. (2016, January 23\u201325). The limitations of deep learning in adversarial settings. Proceedings of the 2016 IEEE European Symposium on Security and Privacy, San Jose, CA, USA.","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref_25","unstructured":"Abadi, M., Barham, P., Chen, J., Chen, Z., Davis, A., Dean, J., Devin, M., Ghemawat, S., Irving, G., and Isard, M. (2016, January 2\u20134). TensorFlow: A System for Large-Scale Machine Learning. Proceedings of the 12th USENIX Symposium on Operating Systems Design and Implementation, Savannah, GA, USA."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"2278","DOI":"10.1109\/5.726791","article-title":"Gradient-based learning applied to document recognition","volume":"86","author":"LeCun","year":"1998","journal-title":"Proc. IEEE"},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"He, K., Zhang, X., Ren, S., and Sun, J. (2016, January 27\u201330). Deep residual learning for image recognition. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Las Vegas, NV, USA.","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"2059","DOI":"10.1109\/TMM.2015.2478068","article-title":"Deep learning and music adversaries","volume":"17","author":"Kereliuk","year":"2015","journal-title":"IEEE Trans. Multimed."}],"container-title":["Symmetry"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2073-8994\/10\/12\/738\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T15:32:54Z","timestamp":1760196774000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2073-8994\/10\/12\/738"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018,12,10]]},"references-count":28,"journal-issue":{"issue":"12","published-online":{"date-parts":[[2018,12]]}},"alternative-id":["sym10120738"],"URL":"https:\/\/doi.org\/10.3390\/sym10120738","relation":{},"ISSN":["2073-8994"],"issn-type":[{"value":"2073-8994","type":"electronic"}],"subject":[],"published":{"date-parts":[[2018,12,10]]}}}