GradMDM : Adversarial Attack on Dynamic Networks

Pan, Jianhong and Foo, Lin Geng and Zheng, Qichen and Fan, Zhipeng and Rahmani, Hossein and Ke, Qiuhong and Liu, Jun (2023) GradMDM : Adversarial Attack on Dynamic Networks. IEEE Transactions on Pattern Analysis and Machine Intelligence, 45 (9). pp. 11374-11381. ISSN 0162-8828

[thumbnail of Layer_wise_Attack]
Text (Layer_wise_Attack)
Layer_wise_Attack.pdf - Accepted Version
Available under License Creative Commons Attribution.

Download (881kB)

Abstract

Dynamic neural networks can greatly reduce computation redundancy without compromising accuracy by adapting their structures based on the input. In this paper, we explore the robustness of dynamic neural networks against \textit{energy-oriented attacks} targeted at reducing their efficiency. Specifically, we attack dynamic models with our novel algorithm GradMDM. GradMDM is a technique that adjusts the direction and the magnitude of the gradients to effectively find a small perturbation for each input, that will activate more computational units of dynamic models during inference. We evaluate GradMDM on multiple datasets and dynamic models, where it outperforms previous energy-oriented attack techniques, significantly increasing computation complexity while reducing the perceptibility of the perturbations.

Item Type:
Journal Article
Journal or Publication Title:
IEEE Transactions on Pattern Analysis and Machine Intelligence
Additional Information:
©2023 IEEE. Personal use of this material is permitted. However, permission to reprint/republish this material for advertising or promotional purposes or for creating new collective works for resale or redistribution to servers or lists, or to reuse any copyrighted component of this work in other works must be obtained from the IEEE.
Uncontrolled Keywords:
/dk/atira/pure/subjectarea/asjc/1700/1702
Subjects:
?? artificial intelligencecomputational theory and mathematicssoftwareapplied mathematicscomputer vision and pattern recognition ??
ID Code:
189850
Deposited By:
Deposited On:
27 Mar 2023 10:10
Refereed?:
Yes
Published?:
Published
Last Modified:
24 Apr 2024 01:32