Boosting the transferability of adversarial attacks with global momentum initialization

被引:3
|
作者
Wang, Jiafeng [1 ]
Chen, Zhaoyu [2 ,3 ]
Jiang, Kaixun [2 ,3 ]
Yang, Dingkang [2 ,3 ]
Hong, Lingyi [1 ]
Guo, Pinxue [2 ,3 ]
Guo, Haijing [1 ]
Zhang, Wenqiang [1 ,2 ,3 ]
机构
[1] Fudan Univ, Sch Comp Sci, Shanghai Key Lab Intelligent Informat Proc, Shanghai 200433, Peoples R China
[2] Fudan Univ, Acad Engn & Technol, Shanghai Engn Res Ctr AI & Robot, Shanghai 200433, Peoples R China
[3] Fudan Univ, Acad Engn & Technol, Engn Res Ctr Robot, Minist Educ, Shanghai 200433, Peoples R China
关键词
Adversarial examples; Black-box attacks; Adversarial transferability; Gradient optimization; Robustness;
D O I
10.1016/j.eswa.2024.124757
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Deep Neural Networks (DNNs) are vulnerable to adversarial examples, which are crafted by adding human- imperceptible perturbations to the benign inputs. Simultaneously, adversarial examples exhibit transferability across models, enabling practical black-box attacks. However, existing methods are still incapable of achieving the desired transfer attack performance. In this work, focusing on gradient optimization and consistency, we analyze the gradient elimination phenomenon as well as the local momentum optimum dilemma. To tackle these challenges, we introduce Global Momentum Initialization (GI), providing global momentum knowledge to mitigate gradient elimination. Specifically, we perform gradient pre-convergence before the attack and a global search during this stage. GI seamlessly integrates with existing transfer methods, significantly improving the success rate of transfer attacks by an average of 6.4% under various advanced defense mechanisms compared to the state-of-the-art method. Ultimately, GI demonstrates strong transferability in both image and video attack domains. Particularly, when attacking advanced defense methods in the image domain, it achieves an average attack success rate of 95.4%. The code is available at https://github.com/Omenzychen/Global-MomentumInitialization.
引用
收藏
页数:10
相关论文
共 50 条
  • [21] Boosting Transferability in Vision-Language Attacks via Diversification Along the Intersection Region of Adversarial Trajectory
    Gao, Sensen
    Jia, Xiaojun
    Rene, Xuhong
    Tsang, Ivor
    Guo, Qing
    COMPUTER VISION-ECCV 2024, PT LVII, 2025, 15115 : 442 - 460
  • [22] Stochastic Variance Reduced Ensemble Adversarial Attack for Boosting the Adversarial Transferability
    Xiong, Yifeng
    Lin, Jiadong
    Zhang, Min
    Hopcroft, John E.
    He, Kun
    2022 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR 2022), 2022, : 14963 - 14972
  • [23] Boosting adversarial attacks with transformed gradient
    He, Zhengyun
    Duan, Yexin
    Zhang, Wu
    Zou, Junhua
    He, Zhengfang
    Wang, Yunyun
    Pan, Zhisong
    COMPUTERS & SECURITY, 2022, 118
  • [24] Boosting Adversarial Attacks with Nadam Optimizer
    Zhang, Qikun
    Zhang, Yuzhi
    Shao, Yanling
    Liu, Mengqi
    Li, Jianyong
    Yuan, Junling
    Wang, Ruifang
    ELECTRONICS, 2023, 12 (06)
  • [25] Gradient Aggregation Boosting Adversarial Examples Transferability Method
    Deng, Shiyun
    Ling, Jie
    Computer Engineering and Applications, 2024, 60 (14) : 275 - 282
  • [26] Boosting Adversarial Transferability by Achieving Flat Local Maxima
    Ge, Zhijin
    Liu, Hongying
    Wang, Xiaosen
    Shang, Fanhua
    Liu, Yuanyuan
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 36 (NEURIPS 2023), 2023,
  • [27] Boosting the Adversarial Transferability of Surrogate Models with Dark Knowledge
    Yang, Dingcheng
    Xiao, Zihao
    Yu, Wenjian
    2023 IEEE 35TH INTERNATIONAL CONFERENCE ON TOOLS WITH ARTIFICIAL INTELLIGENCE, ICTAI, 2023, : 627 - 635
  • [28] Boosting Adversarial Transferability by Batchwise Amplitude Spectrum Normalization
    Dang, Qianlong
    Zhan, Tao
    Gong, Maoguo
    He, Xiaoyu
    IEEE TRANSACTIONS ON GEOSCIENCE AND REMOTE SENSING, 2025, 63
  • [29] Boosting Adversarial Transferability via Gradient Relevance Attack
    Zhu, Hegui
    Ren, Yuchen
    Sui, Xiaoyan
    Yang, Lianping
    Jiang, Wuming
    2023 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION, ICCV, 2023, : 4718 - 4727
  • [30] Improving adversarial transferability through frequency enhanced momentum
    Zhao, Changfei
    Deng, Xinyang
    Jiang, Wen
    INFORMATION SCIENCES, 2024, 665