Improving the transferability of adversarial attacks via self-ensemble

被引:1
|
作者
Cheng, Shuyan [1 ]
Li, Peng [1 ]
Liu, Jianguo [1 ]
Xu, He [1 ]
Yao, Yudong [2 ]
机构
[1] Nanjing Univ Posts & Telecommun, Sch Comp Sci, Nanjing 210023, Peoples R China
[2] Stevens Inst Technol, Dept Elect & Comp Engn, Hoboken, NJ 07030 USA
基金
中国国家自然科学基金;
关键词
Black-box attacks; Transferability; Adversarial examples; Self-ensemble; Feature importance;
D O I
10.1007/s10489-024-05728-z
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Deep neural networks have been used extensively for diverse visual tasks, including object detection, face recognition, and image classification. However, they face several security threats, such as adversarial attacks. To improve the resistance of neural networks to adversarial attacks, researchers have investigated the security issues of models from the perspectives of both attacks and defenses. Recently, the transferability of adversarial attacks has received extensive attention, which promotes the application of adversarial attacks in practical scenarios. However, existing transferable attacks tend to trap into a poor local optimum and significantly degrade the transferability because the production of adversarial samples lacks randomness. Therefore, we propose a self-ensemble-based feature-level adversarial attack (SEFA) to boost transferability by randomly disrupting salient features. We provide theoretical analysis to demonstrate the superiority of the proposed method. In particular, perturbing the refined feature importance weighted intermediate features suppresses positive features and encourages negative features to realize adversarial attacks. Subsequently, self-ensemble is introduced to solve the optimization problem, thus enhancing the diversity from an optimization perspective. The diverse orthogonal initial perturbations disrupt these features stochastically, searching the space of transferable perturbations exhaustively to avoid poor local optima and improve transferability effectively. Extensive experiments show the effectiveness and superiority of the proposed SEFA, i.e., the success rates against undefended models and defense models are improved by 7.7% and 13.4%, respectively, compared with existing transferable attacks. Our code is available at https://github.com/chengshuyan/SEFA.
引用
收藏
页码:10608 / 10626
页数:19
相关论文
共 50 条
  • [21] Improving the Transferability of Adversarial Attacks Through Both Front and Rear Vector Method
    Wu, Hao
    Wang, Jinwei
    Zhang, Jiawei
    Luo, Xiangyang
    Ma, Bin
    DIGITAL FORENSICS AND WATERMARKING, IWDW 2022, 2023, 13825 : 83 - 97
  • [22] Improving transferability of 3D adversarial attacks with scale and shear transformations
    Zhang, Jinlai
    Dong, Yinpeng
    Zhu, Jun
    Zhu, Jihong
    Kuang, Minchi
    Yuan, Xiaming
    INFORMATION SCIENCES, 2024, 662
  • [23] Improving the transferability of adversarial examples through black-box feature attacks
    Wang, Maoyuan
    Wang, Jinwei
    Ma, Bin
    Luo, Xiangyang
    NEUROCOMPUTING, 2024, 595
  • [24] Ensemble Diversity Facilitates Adversarial Transferability
    Tang, Bowen
    Wang, Zheng
    Bin, Yi
    Dou, Qi
    Yang, Yang
    Shen, Heng Tao
    2024 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2024, : 24377 - 24386
  • [25] Improving the Transferability of Adversarial Samples with Adversarial Transformations
    Wu, Weibin
    Su, Yuxin
    Lyu, Michael R.
    King, Irwin
    2021 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION, CVPR 2021, 2021, : 9020 - 9029
  • [26] Boosting Adversarial Transferability via Relative Feature Importance-Aware Attacks
    Li, Jian-Wei
    Shao, Wen-Ze
    Sun, Yu-Bao
    Wang, Li-Qian
    Ge, Qi
    Xiao, Liang
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2025, 20 : 3489 - 3504
  • [27] Boosting the Transferability of Ensemble Adversarial Attack via Stochastic Average Variance Descent
    Zhao, Lei
    Liu, Zhizhi
    Wu, Sixing
    Chen, Wei
    Wu, Liwen
    Pu, Bin
    Yao, Shaowen
    IET INFORMATION SECURITY, 2024, 2024
  • [28] An Adaptive Model Ensemble Adversarial Attack for Boosting Adversarial Transferability
    Chen, Bin
    Yin, Jiali
    Chen, Shukai
    Chen, Bohao
    Liu, Ximeng
    2023 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION, ICCV, 2023, : 4466 - 4475
  • [29] Demystifying the Transferability of Adversarial Attacks in Computer Networks
    Nowroozi, Ehsan
    Mekdad, Yassine
    Berenjestanaki, Mohammad Hajian
    Conti, Mauro
    El Fergougui, Abdeslam
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2022, 19 (03): : 3387 - 3400
  • [30] Improving Adversarial Transferability via Intermediate-level Perturbation Decay
    Li, Qizhang
    Guo, Yiwen
    Zuo, Wangmeng
    Chen, Hao
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 36 (NEURIPS 2023), 2023,