Boosting Adversarial Transferability via Gradient Relevance Attack

被引:17
|
作者
Zhu, Hegui [1 ]
Ren, Yuchen [1 ]
Sui, Xiaoyan [1 ]
Yang, Lianping [1 ]
Jiang, Wuming [2 ]
机构
[1] Northeastern Univ, Coll Sci, Shenyang, Peoples R China
[2] Beijing EyeCool Technol, Beijing, Peoples R China
来源
2023 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION, ICCV | 2023年
关键词
D O I
10.1109/ICCV51070.2023.00437
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Plentiful adversarial attack researches have revealed the fragility of deep neural networks (DNNs), where the imperceptible perturbations can cause drastic changes in the output. Among the diverse types of attack methods, gradient-based attacks are powerful and easy to implement, arousing wide concern for the security problem of DNNs. However, under the black-box setting, the existing gradient-based attacks have much trouble in breaking through DNN models with defense technologies, especially those adversarially trained models. To make adversarial examples more transferable, in this paper, we explore the fluctuation phenomenon on the plus-minus sign of the adversarial perturbations' pixels during the generation of adversarial examples, and propose an ingenious Gradient Relevance Attack (GRA). Specifically, two gradient relevance frameworks are presented to better utilize the information in the neighborhood of the input, which can correct the update direction adaptively. Then we adjust the update step at each iteration with a decay indicator to counter the fluctuation. Experiment results on a subset of the ILSVRC 2012 validation set forcefully verify the effectiveness of GRA. Furthermore, the attack success rates of 68.7% and 64.8% on Tencent Cloud and Baidu AI Cloud further indicate that GRA can craft adversarial examples with the ability to transfer across both datasets and model architectures. Code is released at https://github.com/RYC-98/GRA.
引用
收藏
页码:4718 / 4727
页数:10
相关论文
共 50 条
  • [21] Boosting transferability of adversarial samples via saliency distribution and frequency domain enhancement
    Wang, Yixuan
    Hong, Wei
    Zhang, Xueqin
    Zhang, Qing
    Gu, Chunhua
    KNOWLEDGE-BASED SYSTEMS, 2024, 300
  • [22] Boosting Adversarial Transferability Through Intermediate Feature
    He, Chenghai
    Li, Xiaoqian
    Zhang, Xiaohang
    Zhang, Kai
    Li, Hailing
    Xiong, Gang
    Li, Xuan
    ARTIFICIAL NEURAL NETWORKS AND MACHINE LEARNING, ICANN 2023, PT V, 2023, 14258 : 28 - 39
  • [23] Simple Techniques are Sufficient for Boosting Adversarial Transferability
    Zhang, Chaoning
    Benz, Philipp
    Karjauv, Adil
    Kweon, In So
    Hong, Choong Seon
    PROCEEDINGS OF THE 31ST ACM INTERNATIONAL CONFERENCE ON MULTIMEDIA, MM 2023, 2023, : 8486 - 8494
  • [24] Improving the adversarial transferability with relational graphs ensemble adversarial attack
    Pi, Jiatian
    Luo, Chaoyang
    Xia, Fen
    Jiang, Ning
    Wu, Haiying
    Wu, Zhiyou
    FRONTIERS IN NEUROSCIENCE, 2023, 16
  • [25] Boosting adversarial transferability in vision-language models via multimodal feature heterogeneity
    Chen, Long
    Chen, Yuling
    Ouyang, Zhi
    Dou, Hui
    Zhang, Yangwen
    Sang, Haiwei
    SCIENTIFIC REPORTS, 2025, 15 (01):
  • [26] Spatial-frequency gradient fusion based model augmentation for high transferability adversarial attack
    Pang, Jingfa
    Yuan, Chengsheng
    Xia, Zhihua
    Li, Xinting
    Fu, Zhangjie
    KNOWLEDGE-BASED SYSTEMS, 2024, 301
  • [27] Boosting the transferability of adversarial attacks with global momentum initialization
    Wang, Jiafeng
    Chen, Zhaoyu
    Jiang, Kaixun
    Yang, Dingkang
    Hong, Lingyi
    Guo, Pinxue
    Guo, Haijing
    Zhang, Wenqiang
    EXPERT SYSTEMS WITH APPLICATIONS, 2024, 255
  • [28] Boosting Adversarial Transferability by Achieving Flat Local Maxima
    Ge, Zhijin
    Liu, Hongying
    Wang, Xiaosen
    Shang, Fanhua
    Liu, Yuanyuan
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 36 (NEURIPS 2023), 2023,
  • [29] UNIVERSAL ADVERSARIAL ATTACK VIA ENHANCED PROJECTED GRADIENT DESCENT
    Deng, Yingpeng
    Karam, Lina J.
    2020 IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING (ICIP), 2020, : 1241 - 1245
  • [30] Boosting the Adversarial Transferability of Surrogate Models with Dark Knowledge
    Yang, Dingcheng
    Xiao, Zihao
    Yu, Wenjian
    2023 IEEE 35TH INTERNATIONAL CONFERENCE ON TOOLS WITH ARTIFICIAL INTELLIGENCE, ICTAI, 2023, : 627 - 635