Leveraging Information Consistency in Frequency and Spatial Domain for Adversarial Attacks

被引:0
|
作者
Jin, Zhibo [1 ]
Zhang, Jiayu [2 ]
Zhu, Zhiyu [1 ]
Wang, Xinyi [3 ]
Huang, Yiyun [4 ]
Chen, Huaming [1 ]
机构
[1] Univ Sydney, Sydney, NSW, Australia
[2] Suzhou Yierqi, Suzhou, Peoples R China
[3] Univ Malaya, Kuala Lumpur, Malaysia
[4] Virginia Polytech Inst & State Univ, Blacksburg, VA USA
来源
PRICAI 2024: TRENDS IN ARTIFICIAL INTELLIGENCE, PT I | 2025年 / 15281卷
关键词
Adversarial Attacks; Frequency Analysis; Transferability;
D O I
10.1007/978-981-96-0116-5_8
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Adversarial examples are a key method to exploit deep neural networks. Using gradient information, such examples can be generated in an efficient way without altering the victim model. Recent frequency domain transformation has further enhanced the transferability of such adversarial examples, such as spectrum simulation attack. In this work, we investigate the effectiveness of frequency domain-based attacks, aligning with similar findings in the spatial domain. Furthermore, such consistency between the frequency and spatial domains provides insights into how gradient-based adversarial attacks induce perturbations across different domains, which is yet to be explored. Hence, we propose a simple, effective, and scalable gradient-based adversarial attack algorithm leveraging the information consistency in both frequency and spatial domains. We evaluate the algorithm for its effectiveness against different models. Extensive experiments demonstrate that our algorithm achieves state-of-the-art results compared to other gradient-based algorithms. Our code is available at: https://github.com/LMBTough/FSA.
引用
收藏
页码:93 / 105
页数:13
相关论文
共 50 条
  • [1] Frequency domain regularization for iterative adversarial attacks
    Li, Tengjiao
    Li, Maosen
    Yang, Yanhua
    Deng, Cheng
    PATTERN RECOGNITION, 2023, 134
  • [2] Leveraging Domain Features for Detecting Adversarial Attacks Against Deep Speech Recognition in Noise
    Nielsen, Christian Heider
    Tan, Zheng-Hua
    IEEE OPEN JOURNAL OF SIGNAL PROCESSING, 2023, 4 : 179 - 187
  • [3] Leveraging Adversarial Learning for the Detection of Morphing Attacks
    Blasingame, Zander
    Liu, Chen
    2021 INTERNATIONAL JOINT CONFERENCE ON BIOMETRICS (IJCB 2021), 2021,
  • [4] Characterizing Adversarial Examples Based on Spatial Consistency Information for Semantic Segmentation
    Xiao, Chaowei
    Deng, Ruizhi
    Li, Bo
    Yu, Fisher
    Liu, Mingyan
    Song, Dawn
    COMPUTER VISION - ECCV 2018, PT X, 2018, 11214 : 220 - 237
  • [5] Deepmarking: Leveraging Adversarial Noise for Membership Inference Attacks
    Jelstrup, Malthe Andreas Lejbolle
    Bigdeli, Siavash Arjomand
    2024 IEEE INTERNATIONAL CONFERENCE ON COMPUTATIONAL PHOTOGRAPHY, ICCP 2024, 2024,
  • [6] An Adaptive Image Watermarking Algorithm Leveraging Spatial and Frequency Domain Techniques
    Qu, Chunyi
    Zhang, Junxing
    2017 IEEE 9TH INTERNATIONAL CONFERENCE ON COMMUNICATION SOFTWARE AND NETWORKS (ICCSN), 2017, : 1276 - 1281
  • [7] ADVERSARIAL SPATIAL FREQUENCY DOMAIN CRITIC LEARNING FOR AGE AND GENDER CLASSIFICATION
    Lee, Sangmin S.
    Kim, Hak Gu
    Kim, Kihyun
    Ro, Yong Man
    2018 25TH IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING (ICIP), 2018, : 2032 - 2036
  • [8] Frequency domain-based reversible adversarial attacks for privacy protection in Internet of Things
    Lu, Yang
    Ma, Tianfeng
    Pang, Zilong
    Chai, Xiuli
    Chen, Zhen
    Tang, Zongwei
    JOURNAL OF ELECTRONIC IMAGING, 2024, 33 (04)
  • [9] Mel frequency spectral domain defenses against adversarial attacks on speech recognition systems
    Mehlman, Nicholas
    Sreeram, Anirudh
    Peri, Raghuveer
    Narayanan, Shrikanth
    JASA EXPRESS LETTERS, 2023, 3 (03):
  • [10] Leveraging transferability and improved beam search in textual adversarial attacks
    Zhu, Bin
    Gu, Zhaoquan
    Qian, Yaguan
    Lau, Francis
    Tian, Zhihong
    NEUROCOMPUTING, 2022, 500 : 135 - 142