Minimal adversarial attack on the \(L_0\) norm
摘要
The concept of adversarial machine learning has become a central research area within the domain of artificial intelligence, focusing on how machine learning systems can be exploited for malicious purposes. This is particularly relevant in computer vision, where adversarial attacks pose significant security risks in areas such as autonomous vehicle and weapon detection. These attacks aim to modify correctly classified images with minor modifications to convert them into adversarial instances to deceive machine learning models. This paper introduces a novel white-box attack based on an optimization process with the objective to minimize the number of altered pixels during the creation of adversarial images. To this end, we design a novel algorithm called the Minimal