Simple Techniques are Sufficient for Boosting Adversarial Transferability

被引:0
|
作者
Zhang, Chaoning [1 ]
Benz, Philipp [2 ]
Karjauv, Adil [3 ]
Kweon, In So [3 ]
Hong, Choong Seon [1 ]
机构
[1] Kyung Hee Univ, Seoul, South Korea
[2] Deeping Source, Seoul, South Korea
[3] Korea Adv Inst Sci & Technol, Daejeon, South Korea
基金
新加坡国家研究基金会;
关键词
Adversarial Transferability; Transferable Attacks; Targeted Attacks;
D O I
10.1145/3581783.3612598
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Transferable targeted adversarial attack against deep image classifiers has remained an open issue. Depending on the space to optimize the loss, the existing methods can be divided into two categories: (a) feature space attack and (b) output space attack. The feature space attack outperforms output space one by a large margin but at the cost of requiring the training of layer-wise auxiliary classifiers for each corresponding target class together with the greedy search for the optimal layers. In this work, we revisit the method of output space attack and improve it from two perspectives. First, we identify over-fitting as one major factor that hinders transferability, for which we propose to augment the network input and/or feature layers with noise. Second, we propose a new cross-entropy loss with two ends: one for pushing the sample far from the source class, i.e. ground-truth class, and the other for pulling it close to the target class. We demonstrate that simple techniques are sufficient enough for achieving very competitive performance.
引用
收藏
页码:8486 / 8494
页数:9
相关论文
共 50 条
  • [21] Boosting Transferability of Targeted Adversarial Examples via Hierarchical Generative Networks
    Yang, Xiao
    Dong, Yinpeng
    Pang, Tianyu
    Su, Hang
    Zhu, Jun
    COMPUTER VISION - ECCV 2022, PT IV, 2022, 13664 : 725 - 742
  • [22] Boosting Adversarial Transferability with Shallow-Feature Attack on SAR Images
    Lin, Gengyou
    Pan, Zhisong
    Zhou, Xingyu
    Duan, Yexin
    Bai, Wei
    Zhan, Dazhi
    Zhu, Leqian
    Zhao, Gaoqiang
    Li, Tao
    REMOTE SENSING, 2023, 15 (10)
  • [23] Boosting the transferability of adversarial attacks with adaptive points selecting in temporal neighborhood
    Zhu, Hegui
    Zheng, Haoran
    Zhu, Ying
    Sui, Xiaoyan
    INFORMATION SCIENCES, 2023, 641
  • [24] LGV: Boosting Adversarial Example Transferability from Large Geometric Vicinity
    Gubri, Martin
    Cordy, Maxime
    Papadakis, Mike
    Le Traon, Yves
    Sen, Koushik
    COMPUTER VISION - ECCV 2022, PT IV, 2022, 13664 : 603 - 618
  • [25] Enhancing the transferability of adversarial samples with random noise techniques
    Huang, Jiahao
    Wen, Mi
    Wei, Minjie
    Bi, Yanbing
    COMPUTERS & SECURITY, 2024, 136
  • [26] Probability-Distribution-Guided Adversarial Sample Attacks for Boosting Transferability and Interpretability
    Li, Hongying
    Yu, Miaomiao
    Li, Xiaofei
    Zhang, Jun
    Li, Shuohao
    Lei, Jun
    Huang, Hairong
    MATHEMATICS, 2023, 11 (13)
  • [27] Boosting Adversarial Transferability across Model Genus by Deformation-Constrained Warping
    Lin, Qinliang
    Luo, Cheng
    Niu, Zenghao
    He, Xilin
    Xie, Weicheng
    Hou, Yuanbo
    Shen, Linlin
    Song, Siyang
    THIRTY-EIGHTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, VOL 38 NO 4, 2024, : 3459 - 3467
  • [28] Boosting Adversarial Transferability via Relative Feature Importance-Aware Attacks
    Li, Jian-Wei
    Shao, Wen-Ze
    Sun, Yu-Bao
    Wang, Li-Qian
    Ge, Qi
    Xiao, Liang
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2025, 20 : 3489 - 3504
  • [29] MixCam-attack: Boosting the transferability of adversarial examples with targeted data augmentation
    Guo, Sensen
    Li, Xiaoyu
    Zhu, Peican
    Wang, Baocang
    Mu, Zhiying
    Zhao, Jinxiong
    INFORMATION SCIENCES, 2024, 657
  • [30] Boosting the Transferability of Ensemble Adversarial Attack via Stochastic Average Variance Descent
    Zhao, Lei
    Liu, Zhizhi
    Wu, Sixing
    Chen, Wei
    Wu, Liwen
    Pu, Bin
    Yao, Shaowen
    IET INFORMATION SECURITY, 2024, 2024