One Pixel Attack for Fooling Deep Neural Networks

Jiawei SuDanilo Vasconcellos VargasSakurai Kouichi

article2017IEEE TEVC2,611 citations

Demonstrates that modifying just a single pixel through differential evolution can reliably fool deep neural networks in black-box settings, exposing extreme blind spots in standard image classifiers.

Listen

The article examines the vulnerability of deep neural networks to adversarial attacks in an extremely constrained setting where only a single pixel in an input image can be altered. This matters because prior work on such attacks typically modified many pixels, potentially making changes visible to humans, while the security of image recognition systems used in applications like autonomous vehicles or security cameras depends on understanding even minimal perturbations.

The article set out to determine whether one-pixel modifications could reliably fool common deep neural networks on standard image classification benchmarks and to demonstrate a practical method for generating such attacks.

Researchers applied differential evolution, a population-based optimization technique that requires only the model's output probability labels and no internal details such as gradients, to search for effective single-pixel changes. Experiments used three widely studied network architectures on the Kaggle CIFAR-10 test set of 500 images, the original CIFAR-10 test set, and the BVLC AlexNet on 105 randomly selected ImageNet images.

The analysis shows that one-pixel changes succeeded in 68.71 percent, 71.66 percent, and 63.53 percent of non-targeted attacks on the three CIFAR-10 networks, with average confidence around 74 percent; each image could be shifted to roughly two other classes on average. On ImageNet the success rate reached 16.04 percent with 22.91 percent average confidence. Increasing the limit to three or five pixels raised both success rates and the number of reachable classes, while random single-pixel changes performed substantially worse than the evolutionary search.

These results indicate that current networks remain sensitive to very low-dimensional perturbations, implying that defenses based solely on detecting larger distortions may miss simple attacks and that robustness testing should include such minimal-change scenarios. The approach also illustrates how evolutionary algorithms can efficiently probe model weaknesses without requiring white-box access.

The article recommends using the generated adversarial examples to augment training data for more robust models and extending the method to other domains such as speech or text. Further work is needed to test larger image resolutions, evaluate detection methods against this attack, and explore more advanced evolutionary variants for higher efficiency.

The findings rest on specific datasets and a fixed number of optimization evaluations; success rates could vary with different preprocessing, network training, or larger search budgets, so caution is warranted when generalizing beyond the tested conditions.

Cover for One Pixel Attack for Fooling Deep Neural Networks

Abstract

Recent research has revealed that the output of Deep Neural Networks (DNN) can be easily altered by adding relatively small perturbations to the input vector. In this paper, we analyze an attack in an extremely limited scenario where only one pixel can be modified. For that we propose a novel method for generating one-pixel adversarial perturbations based on differential evolution (DE). It requires less adversarial information (a black-box attack) and can fool more types of networks due to the inherent features of DE. The results show that 67.97% of the natural images in Kaggle CIFAR-10 test dataset and 16.04% of the ImageNet (ILSVRC 2012) test images can be perturbed to at least one target class by modifying just one pixel with 74.03% and 22.91% confidence on average. We also show the same vulnerability on the original CIFAR-10 dataset. Thus, the proposed attack explores a different take on adversarial machine learning in an extreme limited scenario, showing that current DNNs are also vulnerable to such low dimension attacks. Besides, we also illustrate an important application of DE (or broadly speaking, evolutionary computation) in the domain of adversarial machine learning: creating tools that can effectively generate low-cost adversarial attacks against neural networks for evaluating robustness.

Table of Contents

  • I Introduction
  • II Related works
  • III Methodology
  • III-A Problem Description
  • III-B Differential Evolution
  • III-C Method and Settings
  • IV Evaluation and Results
  • IV-A Kaggle CIFAR-10
  • IV-B ImageNet
  • IV-C Results
  • IV-C1 Success Rate and Adversarial Probability Labels (Targeted Attack Results)
  • IV-C2 Number of Target Classes (Non-targeted Attack Results)
  • IV-C3 Original-Target Class Pairs
  • IV-C4 Time complexity and average distortion
  • IV-C5 Comparing with Random One-Pixel Attack
  • IV-C6 Change in fitness values
  • V Results on Original CIFAR-10 Test Data
  • VI Discussion
  • VI-A Adversarial Perturbation
  • VI-B Robustness of One-pixel Attack
  • VII Future Work
  • VIII Acknowledgment
  • References

Knowls

  1. Knowl 1 — Problem Formulation of Few-Pixel and One-Pixel Adversarial Attacks

    equation

    In an image classification setting, let ff denote the target classifier that maps an nn-dimensional input image vector x=(x1,au,xn)x = (x_1, au, x_n) to class prediction probabilities, where ft(x)f_t(x) is the predicted probability that xx belongs to the ground-truth class tt. An additive adversarial perturbation vector e(x)=(e1,au,en)e(x) = (e_1, au, e_n) modifies the input to x+e(x)x + e(x).

    For a targeted attack aiming to force the classifier to predict an arbitrary target adversarial class advt\text{adv} \neq t, the few-pixel perturbation is formulated as an optimization problem under an L0L_0 constraint:

    maxe(x)fadv(x+e(x))subject toe(x)0d\max_{e(x)} f_{\text{adv}}(x + e(x)) \quad \text{subject to} \quad \|e(x)\|_0 \le d

    where e(x)0\|e(x)\|_0 is the L0L_0 pseudo-norm counting the number of non-zero elements (modified dimensions/pixels) in e(x)e(x), and dd is a small integer representing the perturbation budget. For a one-pixel attack, d=1d = 1, restricting the search to 1-dimensional orthogonal slices parallel to coordinate axes in the input space without placing a bound on the modification magnitude along the perturbed dimension. For non-targeted attacks, the objective is to minimize the probability of the true class ft(x+e(x))f_t(x + e(x)) or maximize the probability of the highest non-true class.

  2. Knowl 2 — Differential Evolution Algorithm for One-Pixel Adversarial Attack

    algorithm

    The one-pixel attack utilizes Differential Evolution (DE), a population-based black-box meta-heuristic optimization algorithm that optimizes the perturbation using only feedback from the output probabilities of the target deep neural network without requiring gradient or architectural knowledge.

    Input: Target classifier ff, natural image xx, target class adv\text{adv} (for targeted) or true class tt (for non-targeted), population size N=400N = 400, maximum generations Gmax=100G_{\max} = 100, scale parameter F=0.5F = 0.5, coordinate bounds [1,W][1, W] and [1,H][1, H]
    Output: Best adversarial perturbation e(x)e^*(x)
    Initialize population P={p1,,pN}P = \{p_1, \dots, p_N\}, where each candidate solution pi=(xi,yi,ri,gi,bi)p_i = (x_i, y_i, r_i, g_i, b_i) has coordinates xiU(1,W)x_i \sim U(1, W), yiU(1,H)y_i \sim U(1, H), and RGB values ri,gi,biN(μ=128,σ=127)r_i, g_i, b_i \sim \mathcal{N}(\mu = 128, \sigma = 127)
    for generation g=1g = 1 to GmaxG_{\max} do
        for i=1i = 1 to NN do
            Sample mutually distinct random indices r1,r2,r3{1,,N}{i}r_1, r_2, r_3 \in \{1, \dots, N\} \setminus \{i\}
            Generate mutant candidate (child) ci=pr1+F(pr2pr3)c_i = p_{r_1} + F \cdot (p_{r_2} - p_{r_3})
            Clamp coordinates of cic_i to valid image boundaries and RGB values to [0,255][0, 255]
            Evaluate fitness: fitness(p)=fadv(x+ep)\text{fitness}(p) = f_{\text{adv}}(x + e_p) for targeted attack, or fitness(p)=ft(x+ep)\text{fitness}(p) = -f_t(x + e_p) for non-targeted attack
            if fitness(ci)>fitness(pi)\text{fitness}(c_i) > \text{fitness}(p_i) then
                picip_i \leftarrow c_i
            end if
        end for
        Let p=argmaxpPfitness(p)p^* = \arg\max_{p \in P} \text{fitness}(p)
        if targeted attack and fadv(x+ep)0.90f_{\text{adv}}(x + e_{p^*}) \ge 0.90 then
            return epe_{p^*}
        end if
        if non-targeted attack and ft(x+ep)0.05f_t(x + e_{p^*}) \le 0.05 then
            return epe_{p^*}
        end if
    end for
    return epe_{p^*}

    No crossover operation is used in the candidate generation step. Crossover is omitted to preserve the 5-element coordinate-color tuple structure.

  3. Knowl 3 — One-Pixel, Three-Pixel, and Five-Pixel Attack Results on Kaggle CIFAR-10

    data/table

    The effectiveness of one-pixel, three-pixel, and five-pixel attacks was evaluated across 500 randomly sampled test images from the Kaggle CIFAR-10 dataset against three network architectures: All Convolutional Network (AllConv), Network in Network (NiN), and VGG16. For targeted attacks, 9 distinct targets were tested per image (resulting in 36,000 total targeted evaluations). Non-targeted attack success corresponds to finding at least one target class that flips the original classification.

    Metric AllConv NiN VGG16 BVLC AlexNet
    Original Accuracy 85.6% 87.2% 83.3% 57.3%
    Targeted Success Rate (1 pixel) 19.82% 23.15% 16.48%
    Non-targeted Success Rate (1 pixel) 68.71% 71.66% 63.53% 16.04%
    Target Class Confidence (1 pixel) 79.40% 75.02% 67.67% 22.91%
    Metric 3 pixels (AllConv) 5 pixels (NiN)
    Targeted Success Rate 40.57% 44.00%
    Non-targeted Success Rate 86.53% 86.34%
    Target Class Confidence 79.17% 77.09%

    Increasing the perturbation budget from one pixel to three and five pixels increases the non-targeted success rate from roughly 68%71%68\%\text{--}71\% to over 86%86\%, and roughly doubles the targeted success rate while retaining average adversarial confidence above 77%77\%.

  4. Knowl 4 — One-Pixel Non-Targeted Attack Effectiveness on ImageNet

    empirical result

    The one-pixel non-targeted attack generalizes to high-resolution datasets. Testing against the BVLC AlexNet model on 105 randomly sampled ILSVRC 2012 test images (converted losslessly to PNG and resized to 227×227227 \times 227) yielded a non-targeted attack success rate of 16.04%16.04\%.

    Although the search space on ImageNet (227×227227 \times 227) is approximately 50 times larger than CIFAR-10 (32×3232 \times 32), the attack succeeded with the same number of DE evaluations. For successful attacks on AlexNet, the winning adversarial class achieved an average confidence of 22.91%22.91\%. Because the remaining 999 ImageNet classes divide the remaining probability mass, a confidence of 22.91%22.91\% represents the dominant predicted class and reduces the network's soft label distribution to a nearly uniform state.

  5. Knowl 5 — Comparison of Differential Evolution Versus Random Search for One-Pixel Attacks

    data/table

    To assess whether Differential Evolution is superior to naive exploration, DE was compared against a random search baseline on the Kaggle CIFAR-10 dataset under an equal computational budget of 80,000 evaluations per image (DE: population size 400 with 200 generations; Random Search: 100 random trials with 800 random pixel evaluations per trial).

    Method / Metric AllConv NiN VGG16
    DE Success Rate 68.71% 71.66% 63.53%
    DE Target Confidence 79.40% 75.02% 67.67%
    Random Search Success Rate 49.70% 41.72% 15.57%
    Random Search Target Confidence 87.73% 75.83% 59.90%

    DE outperforms random search by absolute margins of 19.01%19.01\%, 29.94%29.94\%, and 47.96%47.96\% on AllConv, NiN, and VGG16, respectively. While random search finds vulnerable pixels on AllConv and NiN around 42%50%42\%\text{--}50\% of the time, it performs poorly on VGG16 (15.57%15.57\%), where DE maintains robust search efficiency (63.53%63.53\%).

  6. Knowl 6 — One-Pixel Attack Evaluation on the Original Clean CIFAR-10 Test Dataset

    data/table

    Evaluating the one-pixel attack on 500 clean, correctly classified test images from the original CIFAR-10 test set provides a baseline without Kaggle noise. Early stopping was triggered when the target class probability exceeded the true class probability.

    Attack Type AllConv NiN VGG16
    Targeted Success Rate 3.41% 4.78% 5.63%
    Calculated Non-targeted Success Rate 22.67% 32.00% 30.33%
    Targeted Confidence 54.58% 55.18% 51.19%
    Direct Non-targeted Success Rate 22.60% 35.20% 31.40%
    Direct Non-targeted Confidence 56.57% 60.08% 53.58%

    On clean CIFAR-10 images, networks exhibit higher robustness (success rates of 22.60%35.20%22.60\%\text{--}35.20\%) compared to noisy Kaggle images (63.53%71.66%63.53\%\text{--}71.66\%), due to higher baseline classification certainty on clean inputs.

  7. Knowl 7 — Comparison of One-Pixel Attack with LSA and FGSM

    data/table

    The table below compares the non-targeted attack performance of the one-pixel DE attack against the Local Search Attack (LSA) and the Fast Gradient Sign Method (FGSM) on clean CIFAR-10 images.

    Method Success Rate Confidence Modified Pixels Network
    One-Pixel Attack (DE) 35.20% 60.08% 1 (0.098%) NiN
    One-Pixel Attack (DE) 31.40% 53.58% 1 (0.098%) VGG16
    LSA 97.89% 72% 33 (3.24%) NiN
    LSA 97.98% 77% 30 (2.99%) VGG16
    FGSM 93.67% 93% 1024 (100%) NiN
    FGSM 90.93% 90% 1024 (100%) VGG16

    While LSA and FGSM achieve >90%>90\% success rates by modifying approximately 3%3\% and 100%100\% of all image pixels respectively, the one-pixel attack modifies only a single pixel (0.098%0.098\% of a 32×3232 \times 32 image) while still achieving over 31%35%31\%\text{--}35\% non-targeted success.

  8. Knowl 8 — Computational Cost and Distortion Metrics of the One-Pixel Attack

    data/table

    The computational complexity and the magnitude of perturbation required to produce adversarial images were quantified using the average number of model evaluations (population size ×\times generation number) and average single-channel color distortion across RGB channels for successful one-pixel attacks.

    Metric AllConv NiN VGG16 BVLC AlexNet
    Average Evaluations 16,000 12,400 20,000 25,600
    Average Distortion per Channel 123 133 145 158

    Across all four architectures, an adversarial sample is produced in 12,400 to 25,600 evaluations on average. The average distortion per RGB channel (scaled in [0,255][0, 255]) ranges between 123 and 158.

  9. Knowl 9 — Transferability Asymmetries and Geometrical Characteristics of Class Decision Boundaries

    empirical result

    Analyzing original-target class confusion matrices from one-pixel attacks reveals geometric properties of deep neural network decision boundaries:

    1. Directional Vulnerability and Class Symmetry: Many class pairs exhibit symmetric transferability (e.g., Cat \leftrightarrow Dog transitions are mutually frequent, whereas Cat \to Automobile transitions rarely succeed).
    2. Class-Pair Asymmetries: Specific pairs show pronounced directional asymmetry; for instance, attacks from Ship to Airplane succeed frequently on NiN, but Airplane to Ship transitions fail.
    3. Multi-Class Reachability: Individual natural images are frequently located near boundaries of multiple decision regions; on Kaggle CIFAR-10, an average natural image can be perturbed to approximately 1.5 to 2.1 distinct target classes with a single pixel modification, and rare natural images can be perturbed into all 9 other classes with single-pixel changes.
    4. Linearity Hypothesis Contradiction: The success of 1-pixel perturbations demonstrates that the hypothesis that adversarial vulnerability arises solely from the accumulation of tiny modifications across thousands of dimensions is not necessary to explain DNN fragility.
  10. Knowl 10 — Vulnerability to Input Pre-Processing Defenses in $L_0$ Attacks

    limitation

    Because the one-pixel attack places all of its perturbation magnitude into a single isolated coordinate without restricting per-channel color changes, it acts as an extreme L0L_0 attack. Consequently, it is susceptible to image pre-processing defenses designed to identify high-frequency noise and spatial outliers, such as bit-depth feature squeezing, local spatial smoothing filters, and median filtering. Defending systems can detect or remove isolated pixel anomalies prior to classification, though such pre-processing pipelines introduce computational overhead that can impede real-time or high-frame-rate computer vision tasks.

Coverage note — Omitted speculative future work discussions regarding neuroevolutionary architectures (e.g., SUNA) and learning classifier systems as general-purpose defenses, as they represent contextual commentary rather than direct contributions of the paper.

References

  1. 1.M. Barreno, B. Nelson, A. D. Joseph, and J. Tygar. The security of machine learning. Machine Learning, 81(2): pp.121–148, 2010.
  2. 2.M. Barreno, B. Nelson, R. Sears, A. D. Joseph, and J. D. Tygar. Can machine learning be secure? In Proceedings of the 2006 ACM Symposium on Information, computer and communications security, pp.16–25. ACM, 2006.
  3. 3.J. Brest, S. Greiner, B. Boskovic, M. Mernik, and V. Zumer. Self-adapting control parameters in differential evolution: A comparative study on numerical benchmark problems. IEEE transactions on evolutionary computation, 10(6): pp.646–657, 2006.
  4. 4.P. Civicioglu and E. Besdok. A conceptual comparison of the cuckoo-search, particle swarm optimization, differential evolution and artificial bee colony algorithms. Artificial intelligence review, pp.1–32, 2013.
  5. 5.H. Dang, Y. Huang, and E.-C. Chang. Evading classifiers by morphing in the dark. 2017.
  6. 6.S. Das and P. N. Suganthan. Differential evolution: A survey of the state-of-the-art. IEEE transactions on evolutionary computation, 15(1): pp.4–31, 2011.
  7. 7.S. M. Moosavi Dezfooli, F. Alhussein and F. Pascal. Deepfool: a simple and accurate method to fool deep neural networks. In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, pp.2574–2582, 2016.
  8. 8.S. M. Moosavi Dezfooli, F. Alhussein, F. Omar, F. Pascal, and S. Stefano. Analysis of universal adversarial perturbations. arXiv preprint arXiv:1705.09554, 2017.
  9. 9.A. Fawzi, S. M. Moosavi Dezfooli, and P. Frossard. The robustness of deep networks: A geometrical perspective. IEEE Signal Processing Magazine, 34(6): pp.50-62.
  10. 10.A. Fawzi, S.-M. Moosavi-Dezfooli, P. Frossard, and S. Soatto. Classification regions of deep neural networks. arXiv preprint arXiv:1705.09552, 2017.
  11. 11.I. J. Goodfellow, J. Shlens, and C. Szegedy. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572, 2014.
  12. 12.A. Krizhevsky and G. Hinton. Learning multiple layers of features from tiny images. Technical report, (1)4: pp. 7, University of Toronto.2009.
  13. 13.M. Lin, Q. Chen, and S. Yan. Network in network. arXiv preprint arXiv:1312.4400, 2013.
  14. 14.S. M. Moosavi Dezfooli, A. Fawzi, O. Fawzi, and P. Frossard. Universal adversarial perturbations. In Proceedings of 2017 IEEE Conference on Computer Vision and Pattern Recognition (CVPR), number EPFL-CONF-226156, 2017.
  15. 15.N. Narodytska and S. Kasiviswanathan. Simple black-box adversarial attacks on deep neural networks. In 2017 IEEE Conference on Computer Vision and Pattern Recognition Workshops (CVPRW), pp.1310–1318. IEEE, 2017.
  16. 16.A. Nguyen, J. Yosinski, and J. Clune. Deep neural networks are easily fooled: High confidence predictions for unrecognizable images. In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, pp.427–436, 2015.
  17. 17.N. Papernot, P. McDaniel, I. Goodfellow, S. Jha, Z. B. Celik, and A. Swami. Practical black-box attacks against machine learning. In Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security, pp.506–519. ACM, 2017.
  18. 18.N. Papernot, P. McDaniel, S. Jha, M. Fredrikson, Z. B. Celik, and A. Swami. The limitations of deep learning in adversarial settings. In Security and Privacy (EuroS&P), 2016 IEEE European Symposium on, pp.372–387. IEEE, 2016.
  19. 19.A. Rozsa, E. M. Rudd, and T. E. Boult. Adversarial diversity and hard positive generation. In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition Workshops, pp.25–32, 2016.
  20. 20.K. Simonyan, A. Vedaldi, and A. Zisserman. Deep inside convolutional networks: Visualising image classification models and saliency maps. arXiv preprint arXiv:1312.6034, 2013.
  21. 21.K. Simonyan and A. Zisserman. Very deep convolutional networks for large-scale image recognition. arXiv preprint arXiv:1409.1556, 2014.
  22. 22.J. Springenberg, A. Dosovitskiy, T. Brox, and M. Riedmiller. Striving for simplicity: The all convolutional net. In ICLR (workshop track).
  23. 23.R. Storn and K. Price. Differential evolution–a simple and efficient heuristic for global optimization over continuous spaces. Journal of global optimization, 11(4): pp.341–359, 1997.
  24. 24.S. Christian, Z. Wojciech, S. Ilya, b. Joan, E. Dumitru, G. Ian, F. Rob. Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199, 2013.
  25. 25.Y. Taigman, M. Yang, M. Ranzato, and L. Wolf. Deepface: Closing the gap to human-level performance in face verification. In Proceedings of the IEEE conference on computer vision and pattern recognition, pp.1701–1708, 2014.
  26. 26.D. V. Vargas and J. Murata. Spectrum-diverse neuroevolution with unified neural models. IEEE transactions on neural networks and learning systems, 28(8):pp.1759–1773, 2017.
  27. 27.D. V. Vargas, J. Murata, H. Takano, and A. C. B. Delbem. General subpopulation framework and taming the conflict inside populations. Evolutionary computation, 23(1):pp.1–36, 2015.
  28. 28.D. Wei, B. Zhou, A. Torrabla, and W. Freeman. Understanding intra-class knowledge inside cnn. arXiv preprint arXiv:1507.02379, 2015.
  29. 29.J. Yosinski, J. Clune, T. Fuchs, and H. Lipson. Understanding neural networks through deep visualization. arXiv preprint arXiv:1506.06579, 2015.
  30. 30.M. D. Zeiler and R. Fergus. Visualizing and understanding convolutional networks. In European conference on computer vision, pp.818–833. Springer, 2014.
  31. 31.J. Su, D. Vargas, and K. Sakurai. One pixel attack for fooling deep neural networks. arXiv preprint arXiv:1710.08864, 2017.
  32. 32.N. Hansen. The CMA evolution strategy: a comparing review In Towards a new evolutionary computation, pp.75–102. Springer, 2006.
  33. 33.A. Moustafa, B. Bharathan, S. Mani. Did you hear that? Adversarial Examples Against Automatic Speech Recognition. arXiv preprint arXiv:1801.00554, 2018.
  34. 34.P. Nicolas, M. Patrick, S. Ananthram, H. Richard. Crafting Adversarial Input Sequences for Recurrent Neural Networks. arXiv preprint arXiv:1604.08275, 2016.
  35. 35.G. Kathrin, P. Nicolas, M. Praveen, B. Michael, M. Patrick. Adversarial Perturbations Against Deep Neural Networks for Malware Classification. arXiv preprint arXiv:1606.04435, 2016.
  36. 36.E. Logan, T. Brandon, T. Dimitris, S. Ludwig, M. Aleksander. A Rotation and a Translation Suffice: Fooling CNNs with Simple Transformations. arXiv preprint arXiv:1712.02779, 2017.
  37. 37.G. Kathrin, P. Nicolas, M. Praveen, B. Michael, M. Patrick. Adversarial Perturbations Against Deep Neural Networks for Malware Classification. arXiv preprint arXiv:1606.04435, 2016.
  38. 38.M. Sharif, L. Bauer, MK. Reiter On the Suitability of Lp-norms for Creating and Preventing Adversarial Examples. arXiv preprint arXiv:1802.09653, 2018.
  39. 39.X. Yuan, P. He, Q. Zhu, R. R. Bhat Adversarial Examples: Attacks and Defenses for Deep Learning. arXiv preprint arXiv:1712.07107, 2017.
  40. 40.N. Papernot, P. McDaniel, X. Wu, S. Jha, A. Swami Distillation as a defense to adversarial perturbations against deep neural networks. In Proceedings of IEEE Symposium on Security and Privacy (SP), pp.1701–1708.
  41. 41.R. Huang, B. Xu, D. Schuurmans, C. Szepesvri Learning with a strong adversary. arXiv preprint arXiv:1511.03034, 2015.
  42. 42.W. Xu, D. Evans, Y. Qi Feature squeezing: Detecting adversarial examples in deep neural networks arXiv preprint arXiv:1704.01155, 2017.
  43. 43.B. Liang et al. Detecting Adversarial Examples in Deep Networks with Adaptive Noise Reduction. arXiv preprint arXiv:1705.08378, 2017.
  44. 44.K. O. Stanley, R. Miikkulainen. Evolving neural networks through augmenting topologies. In Evolutionary Computation, pp.99–127.
  45. 45.N. Carlini, D. Wagner. Adversarial examples are not easily detected: Bypassing ten detection methods. In Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security, pp.3–14.
  46. 46.N. Carlini, D. Wagner. Defensive distillation is not robust to adversarial examples. arXiv preprint arXiv:1607.04311, 2016.
  47. 47.N. Carlini, D. Wagner. Towards evaluating the robustness of neural networks. In 2017 IEEE Symposium on Security and Privacy (SP), pp.39–57.
  48. 48.H.G. Beyer and H.P. Schwefel. Evolution strategiesA comprehensive introduction. In Natural computing, pp.3–52.
  49. 49.A.K. Qin and P.N. Suganthan. Self-adaptive differential evolution algorithm for numerical optimization. In The 2005 IEEE Congress on Evolutionary Computation, pp.1785–1791.
  50. 50.N. Hansen, S. D. Mller, and P. Koumoutsakos. Reducing the time complexity of the derandomized evolution strategy with covariance matrix adaptation (CMA-ES). In Evol. Comput, pp.1–18.
  51. 51.N. Hansen and A. Ostermeier. Adapting arbitrary normal mutation distributions in evolution strategies: The covariance matrix adaptation. In Proceedings of the 1996 IEEE Conference on Evolutionary Computation, pp.312–317.
  52. 52.N. Hansen and A. Ostermeier. Completely derandomized self-adaptation in evolution strategies. In Evol. Comput, pp.159–195.
  53. 53.D. Whitley, S. Dominic, R. Das and C.W. Anderson. Genetic reinforcement learning for neurocontrol problems. In Machine Learning, pp.259–284.
  54. 54.D.V. Vargas, H. Takano and J. Murata. Self organizing classifiers: first steps in structured evolutionary machine learning. In Evolutionary Intelligence, pp.57–72.
  55. 55.D.V. Vargas, H. Takano and J. Murata. Self organizing classifiers and niched fitness. In Proceedings of the 15th annual conference on Genetic and evolutionary computation, pp.1109–1116.
  56. 56.D.V. Vargas, H. Takano and J. Murata. Novelty-organizing team of classifiers-a team-individual multi-objective approach to reinforcement learning. In Proceedings of the SICE Annual Conference (SICE) , pp.1785–1792.
  57. 57.D.V. Vargas, H. Takano and J. Murata. Novelty-organizing team of classifiers in noisy and dynamic environments. In 2015 IEEE Congress on Evolutionary Computation (CEC), pp.2937–2944.
  58. 58.R.J. Urbanowicz and J.H. Moore. ExSTraCS 2.0: description and evaluation of a scalable learning classifier system. In Evolutionary intelligence, pp.89–116.
  59. 59.I.M. Alvarez, W.N. Browne and M. Zhang. Compaction for code fragment based learning classifier systems. In Australasian Conference on Artificial Life and Computational Intelligence, pp.41–53.
  60. 60.N. Carlini and D. Wagner. Magnet and efficient defenses against adversarial attacks are not robust to adversarial examples. arXiv preprint arXiv:1711.08478, 2017.
  61. 61.A. Abdolmaleki, B. Price, N. Lau, L.P. Reis and G. Neumann. Deriving and improving CMA-ES with information geometric trust regions. In Proceedings of the Genetic and Evolutionary Computation Conference , pp.657–664.
  62. 62.K. Nishida and Y. Akimoto. PSA-CMA-ES: CMA-ES with population size adaptation. In Proceedings of the Genetic and Evolutionary Computation Conference, pp.865–872.
  63. 63.M. Groves and J. Branke. Sequential sampling for noisy optimisation with CMA-ES. In Proceedings of the Genetic and Evolutionary Computation Conference, pp.1023–1030.
  64. 64.CIFAR-10 - Object Recognition in Images@Kaggle. At https://www.kaggle.com/c/cifar-10/data. Accessed date: 1 Feb, 2018.
  65. 65.Jiawei Su, Danilo Vasconcellos Vargas, Kouichi Sakurai One Pixel Attack for Fooling Deep Neural Networks. In IEEE Transactions on Evolutionary Computation, Vol.23 , Issue.5 , pp. 828–841. Publisher: IEEE. DOI: 10.1109/TEVC.2019.2890858.

Citation

MLA
Su, J., et al. “One Pixel Attack for Fooling Deep Neural Networks”. IEEE Transactions on Evolutionary Computation, vol. 23, no. 5, 2019, pp. 828–41, https://doi.org/10.1109/TEVC.2019.2890858.
APA
Su, J., Vargas, D. V., & Sakurai, K. (2019). One Pixel Attack for Fooling Deep Neural Networks. IEEE Transactions on Evolutionary Computation, 23(5), 828–841. https://doi.org/10.1109/TEVC.2019.2890858
Chicago
Su, J., D. V. Vargas, and K. Sakurai. 2019. “One Pixel Attack for Fooling Deep Neural Networks”. IEEE Transactions on Evolutionary Computation 23 (5): 828–41. https://doi.org/10.1109/TEVC.2019.2890858.
Harvard
Su, J., Vargas, D.V. and Sakurai, K. (2019) “One Pixel Attack for Fooling Deep Neural Networks”, IEEE Transactions on Evolutionary Computation, 23(5), pp. 828–841. Available at: https://doi.org/10.1109/TEVC.2019.2890858.
Vancouver
1. Su J, Vargas DV, Sakurai K (2019) One Pixel Attack for Fooling Deep Neural Networks. IEEE Transactions on Evolutionary Computation 23:828–841

BibTeX

@article{Su_2019, title={One Pixel Attack for Fooling Deep Neural Networks}, volume={23}, ISSN={1941-0026}, url={http://dx.doi.org/10.1109/TEVC.2019.2890858}, DOI={10.1109/tevc.2019.2890858}, number={5}, journal={IEEE Transactions on Evolutionary Computation}, publisher={Institute of Electrical and Electronics Engineers (IEEE)}, author={Su, Jiawei and Vargas, Danilo Vasconcellos and Sakurai, Kouichi}, year={2019}, month=Oct, pages={828–841} }
Metadata:Crossref

Access the Paper

This paper is available from its original source. Click below to access the PDF.

Open PDF