Boosting the transferability of adversarial attacks with global momentum initialization

被引:3
|
作者
Wang, Jiafeng [1 ]
Chen, Zhaoyu [2 ,3 ]
Jiang, Kaixun [2 ,3 ]
Yang, Dingkang [2 ,3 ]
Hong, Lingyi [1 ]
Guo, Pinxue [2 ,3 ]
Guo, Haijing [1 ]
Zhang, Wenqiang [1 ,2 ,3 ]
机构
[1] Fudan Univ, Sch Comp Sci, Shanghai Key Lab Intelligent Informat Proc, Shanghai 200433, Peoples R China
[2] Fudan Univ, Acad Engn & Technol, Shanghai Engn Res Ctr AI & Robot, Shanghai 200433, Peoples R China
[3] Fudan Univ, Acad Engn & Technol, Engn Res Ctr Robot, Minist Educ, Shanghai 200433, Peoples R China
关键词
Adversarial examples; Black-box attacks; Adversarial transferability; Gradient optimization; Robustness;
D O I
10.1016/j.eswa.2024.124757
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Deep Neural Networks (DNNs) are vulnerable to adversarial examples, which are crafted by adding human- imperceptible perturbations to the benign inputs. Simultaneously, adversarial examples exhibit transferability across models, enabling practical black-box attacks. However, existing methods are still incapable of achieving the desired transfer attack performance. In this work, focusing on gradient optimization and consistency, we analyze the gradient elimination phenomenon as well as the local momentum optimum dilemma. To tackle these challenges, we introduce Global Momentum Initialization (GI), providing global momentum knowledge to mitigate gradient elimination. Specifically, we perform gradient pre-convergence before the attack and a global search during this stage. GI seamlessly integrates with existing transfer methods, significantly improving the success rate of transfer attacks by an average of 6.4% under various advanced defense mechanisms compared to the state-of-the-art method. Ultimately, GI demonstrates strong transferability in both image and video attack domains. Particularly, when attacking advanced defense methods in the image domain, it achieves an average attack success rate of 95.4%. The code is available at https://github.com/Omenzychen/Global-MomentumInitialization.
引用
收藏
页数:10
相关论文
共 50 条
  • [41] Boosting the Transferability of Video Adversarial Examples via Temporal Translation
    Wei, Zhipeng
    Chen, Jingjing
    Wu, Zuxuan
    Jiang, Yu-Gang
    THIRTY-SIXTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE / THIRTY-FOURTH CONFERENCE ON INNOVATIVE APPLICATIONS OF ARTIFICIAL INTELLIGENCE / THE TWELVETH SYMPOSIUM ON EDUCATIONAL ADVANCES IN ARTIFICIAL INTELLIGENCE, 2022, : 2659 - 2667
  • [42] Toward Understanding and Boosting Adversarial Transferability From a Distribution Perspective
    Zhu, Yao
    Chen, Yuefeng
    Li, Xiaodan
    Chen, Kejiang
    He, Yuan
    Tian, Xiang
    Zheng, Bolun
    Chen, Yaowu
    Huang, Qingming
    IEEE TRANSACTIONS ON IMAGE PROCESSING, 2022, 31 : 6487 - 6501
  • [43] Boosting Model Inversion Attacks With Adversarial Examples
    Zhou, Shuai
    Zhu, Tianqing
    Ye, Dayong
    Yu, Xin
    Zhou, Wanlei
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2024, 21 (03) : 1451 - 1468
  • [44] Transferability of features for neural networks links to adversarial attacks and defences
    Kotyan, Shashank
    Matsuki, Moe
    Vargas, Danilo Vasconcellos
    PLOS ONE, 2022, 17 (04):
  • [45] Leveraging transferability and improved beam search in textual adversarial attacks
    Zhu, Bin
    Gu, Zhaoquan
    Qian, Yaguan
    Lau, Francis
    Tian, Zhihong
    NEUROCOMPUTING, 2022, 500 : 135 - 142
  • [46] Unscrambling the Rectification of Adversarial Attacks Transferability across Computer Networks
    Nowroozi, Ehsan
    Ghelichkhani, Samaneh
    Haider, Imran
    Dehghantanha, Ali
    arXiv, 2023,
  • [47] On the Convergence of an Adaptive Momentum Method for Adversarial Attacks
    Long, Sheng
    Tao, Wei
    Li, Shuohao
    Lei, Jun
    Zhang, Jun
    THIRTY-EIGHTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, VOL 38 NO 13, 2024, : 14132 - 14140
  • [48] Improving the transferability of adversarial attacks via self-ensemble
    Cheng, Shuyan
    Li, Peng
    Liu, Jianguo
    Xu, He
    Yao, Yudong
    APPLIED INTELLIGENCE, 2024, 54 (21) : 10608 - 10626
  • [49] IMPROVING VISUAL QUALITY AND TRANSFERABILITY OF ADVERSARIAL ATTACKS ON FACE RECOGNITION SIMULTANEOUSLY WITH ADVERSARIAL RESTORATION
    Zhou, Fengfan
    Ling, Hefei
    Shi, Yuxuan
    Chen, Jiazhong
    Li, Ping
    2024 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH AND SIGNAL PROCESSING, ICASSP 2024, 2024, : 4540 - 4544
  • [50] The Ultimate Combo: Boosting Adversarial Example Transferability by Composing Data Augmentations
    Yun, Zebin
    Weingarten, Achi-Or
    Ronen, Eyal
    Sharif, Mahmood
    PROCEEDINGS OF THE 2024 WORKSHOP ON ARTIFICIAL INTELLIGENCE AND SECURITY, AISEC 2024, 2024, : 113 - 124