Simple Techniques are Sufficient for Boosting Adversarial Transferability

被引:0
|
作者
Zhang, Chaoning [1 ]
Benz, Philipp [2 ]
Karjauv, Adil [3 ]
Kweon, In So [3 ]
Hong, Choong Seon [1 ]
机构
[1] Kyung Hee Univ, Seoul, South Korea
[2] Deeping Source, Seoul, South Korea
[3] Korea Adv Inst Sci & Technol, Daejeon, South Korea
基金
新加坡国家研究基金会;
关键词
Adversarial Transferability; Transferable Attacks; Targeted Attacks;
D O I
10.1145/3581783.3612598
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Transferable targeted adversarial attack against deep image classifiers has remained an open issue. Depending on the space to optimize the loss, the existing methods can be divided into two categories: (a) feature space attack and (b) output space attack. The feature space attack outperforms output space one by a large margin but at the cost of requiring the training of layer-wise auxiliary classifiers for each corresponding target class together with the greedy search for the optimal layers. In this work, we revisit the method of output space attack and improve it from two perspectives. First, we identify over-fitting as one major factor that hinders transferability, for which we propose to augment the network input and/or feature layers with noise. Second, we propose a new cross-entropy loss with two ends: one for pushing the sample far from the source class, i.e. ground-truth class, and the other for pulling it close to the target class. We demonstrate that simple techniques are sufficient enough for achieving very competitive performance.
引用
收藏
页码:8486 / 8494
页数:9
相关论文
共 50 条
  • [41] On the Adversarial Transferability of ConvMixer Models
    Iijima, Ryota
    Tanaka, Miki
    Echizen, Isao
    Kiya, Hitoshi
    PROCEEDINGS OF 2022 ASIA-PACIFIC SIGNAL AND INFORMATION PROCESSING ASSOCIATION ANNUAL SUMMIT AND CONFERENCE (APSIPA ASC), 2022, : 1826 - 1830
  • [42] Boosting Transferability in Vision-Language Attacks via Diversification Along the Intersection Region of Adversarial Trajectory
    Gao, Sensen
    Jia, Xiaojun
    Rene, Xuhong
    Tsang, Ivor
    Guo, Qing
    COMPUTER VISION-ECCV 2024, PT LVII, 2025, 15115 : 442 - 460
  • [43] Improving the adversarial transferability with relational graphs ensemble adversarial attack
    Pi, Jiatian
    Luo, Chaoyang
    Xia, Fen
    Jiang, Ning
    Wu, Haiying
    Wu, Zhiyou
    FRONTIERS IN NEUROSCIENCE, 2023, 16
  • [44] An approach to improve transferability of adversarial examples
    Zhang, Weihan
    Guo, Ying
    PHYSICAL COMMUNICATION, 2024, 64
  • [45] Remix: Towards the transferability of adversarial examples
    Zhao, Hongzhi
    Hao, Lingguang
    Hao, Kuangrong
    Wei, Bing
    Cai, Xin
    NEURAL NETWORKS, 2023, 163 : 367 - 378
  • [46] Dynamic defenses and the transferability of adversarial examples
    Thomas, Sam
    Koleini, Farnoosh
    Tabrizi, Nasseh
    2022 IEEE 4TH INTERNATIONAL CONFERENCE ON TRUST, PRIVACY AND SECURITY IN INTELLIGENT SYSTEMS, AND APPLICATIONS, TPS-ISA, 2022, : 276 - 284
  • [47] Rethinking the Backward Propagation for Adversarial Transferability
    Wang, Xiaosen
    Tong, Kangheng
    He, Kun
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 36 (NEURIPS 2023), 2023,
  • [48] Enhancing the Adversarial Transferability with Channel Decomposition
    Lin B.
    Gao F.
    Zeng W.
    Chen J.
    Zhang C.
    Zhu Q.
    Zhou Y.
    Zheng D.
    Qiu Q.
    Yang S.
    Computer Systems Science and Engineering, 2023, 46 (03): : 3075 - 3085
  • [49] Ensemble Diversity Facilitates Adversarial Transferability
    Tang, Bowen
    Wang, Zheng
    Bin, Yi
    Dou, Qi
    Yang, Yang
    Shen, Heng Tao
    2024 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2024, : 24377 - 24386
  • [50] A Geometric Perspective on the Transferability of Adversarial Directions
    Charles, Zachary
    Rosenberg, Harrison
    Papailiopoulos, Dimitris
    22ND INTERNATIONAL CONFERENCE ON ARTIFICIAL INTELLIGENCE AND STATISTICS, VOL 89, 2019, 89