Simple Techniques are Sufficient for Boosting Adversarial Transferability

被引:0
|
作者
Zhang, Chaoning [1 ]
Benz, Philipp [2 ]
Karjauv, Adil [3 ]
Kweon, In So [3 ]
Hong, Choong Seon [1 ]
机构
[1] Kyung Hee Univ, Seoul, South Korea
[2] Deeping Source, Seoul, South Korea
[3] Korea Adv Inst Sci & Technol, Daejeon, South Korea
基金
新加坡国家研究基金会;
关键词
Adversarial Transferability; Transferable Attacks; Targeted Attacks;
D O I
10.1145/3581783.3612598
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Transferable targeted adversarial attack against deep image classifiers has remained an open issue. Depending on the space to optimize the loss, the existing methods can be divided into two categories: (a) feature space attack and (b) output space attack. The feature space attack outperforms output space one by a large margin but at the cost of requiring the training of layer-wise auxiliary classifiers for each corresponding target class together with the greedy search for the optimal layers. In this work, we revisit the method of output space attack and improve it from two perspectives. First, we identify over-fitting as one major factor that hinders transferability, for which we propose to augment the network input and/or feature layers with noise. Second, we propose a new cross-entropy loss with two ends: one for pushing the sample far from the source class, i.e. ground-truth class, and the other for pulling it close to the target class. We demonstrate that simple techniques are sufficient enough for achieving very competitive performance.
引用
收藏
页码:8486 / 8494
页数:9
相关论文
共 50 条
  • [31] Boosting transferability of adversarial samples via saliency distribution and frequency domain enhancement
    Wang, Yixuan
    Hong, Wei
    Zhang, Xueqin
    Zhang, Qing
    Gu, Chunhua
    KNOWLEDGE-BASED SYSTEMS, 2024, 300
  • [32] Boosting transferability of targeted adversarial examples with non-robust feature alignment
    Zhu, Hegui
    Sui, Xiaoyan
    Ren, Yuchen
    Jia, Yanmeng
    Zhang, Libo
    EXPERT SYSTEMS WITH APPLICATIONS, 2023, 227
  • [33] Boosting adversarial transferability in vision-language models via multimodal feature heterogeneity
    Chen, Long
    Chen, Yuling
    Ouyang, Zhi
    Dou, Hui
    Zhang, Yangwen
    Sang, Haiwei
    SCIENTIFIC REPORTS, 2025, 15 (01):
  • [34] Boosting Adversarial Transferability Through Adaptive-Learning-Rate with Data Augmentation Mechanism
    Bao L.
    Tao W.
    Tao Q.
    Tien Tzu Hsueh Pao/Acta Electronica Sinica, 2024, 52 (01): : 157 - 169
  • [35] Adaptive Multi-scale Degradation-Based Attack for Boosting the Adversarial Transferability
    Ran, Ran
    Wei, Jiwei
    Zhang, Chaoning
    Wang, Guoqing
    Yang, Yang
    Shen, Heng Tao
    IEEE TRANSACTIONS ON MULTIMEDIA, 2024, 26 : 10979 - 10990
  • [36] Boosting the Transferability of Adversarial Examples with Gradient-Aligned Ensemble Attack for Speaker Recognition
    Li, Zhuhai
    Zhang, Jie
    Guo, Wu
    Wu, Haochen
    INTERSPEECH 2024, 2024, : 532 - 536
  • [37] Improving the Transferability of Adversarial Samples with Adversarial Transformations
    Wu, Weibin
    Su, Yuxin
    Lyu, Michael R.
    King, Irwin
    2021 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION, CVPR 2021, 2021, : 9020 - 9029
  • [38] Uncovering the Connections Between Adversarial Transferability and Knowledge Transferability
    Liang, Kaizhao
    Zhang, Jacky Y.
    Wang, Boxin
    Yang, Zhuolin
    Koyejo, Oluwasanmi
    Li, Bo
    INTERNATIONAL CONFERENCE ON MACHINE LEARNING, VOL 139, 2021, 139
  • [39] Ranking the Transferability of Adversarial Examples
    Levy, Moshe
    Amit, Guy
    Elovici, Yuval
    Mirsky, Yisroel
    ACM TRANSACTIONS ON INTELLIGENT SYSTEMS AND TECHNOLOGY, 2024, 15 (05)
  • [40] Exploring Transferability on Adversarial Attacks
    Alvarez, Enrique
    Alvarez, Rafael
    Cazorla, Miguel
    IEEE ACCESS, 2023, 11 : 105545 - 105556