Leveraging Information Consistency in Frequency and Spatial Domain for Adversarial Attacks

被引:0
作者
Jin, Zhibo [1 ]
Zhang, Jiayu [2 ]
Zhu, Zhiyu [1 ]
Wang, Xinyi [3 ]
Huang, Yiyun [4 ]
Chen, Huaming [1 ]
机构
[1] Univ Sydney, Sydney, NSW, Australia
[2] Suzhou Yierqi, Suzhou, Peoples R China
[3] Univ Malaya, Kuala Lumpur, Malaysia
[4] Virginia Polytech Inst & State Univ, Blacksburg, VA USA
来源
PRICAI 2024: TRENDS IN ARTIFICIAL INTELLIGENCE, PT I | 2025年 / 15281卷
关键词
Adversarial Attacks; Frequency Analysis; Transferability;
D O I
10.1007/978-981-96-0116-5_8
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Adversarial examples are a key method to exploit deep neural networks. Using gradient information, such examples can be generated in an efficient way without altering the victim model. Recent frequency domain transformation has further enhanced the transferability of such adversarial examples, such as spectrum simulation attack. In this work, we investigate the effectiveness of frequency domain-based attacks, aligning with similar findings in the spatial domain. Furthermore, such consistency between the frequency and spatial domains provides insights into how gradient-based adversarial attacks induce perturbations across different domains, which is yet to be explored. Hence, we propose a simple, effective, and scalable gradient-based adversarial attack algorithm leveraging the information consistency in both frequency and spatial domains. We evaluate the algorithm for its effectiveness against different models. Extensive experiments demonstrate that our algorithm achieves state-of-the-art results compared to other gradient-based algorithms. Our code is available at: https://github.com/LMBTough/FSA.
引用
收藏
页码:93 / 105
页数:13
相关论文
共 31 条
[21]   Enhancing robust node classification via information competition: An improved adversarial resilience method for graph attacks [J].
Yong Huang ;
Yao Yang ;
Qiao Han ;
Xinling Guo ;
Yiteng Zhai ;
Baoping Cheng .
Applied Intelligence, 2025, 55 (10)
[22]   A High-Transferability Adversarial Sample Generation Method Incorporating Frequency Domain Transformations [J].
Yan, Sijian ;
Deng, Zhengjie ;
Dong, Jiale ;
Li, Xiyan .
ELECTRONICS, 2024, 13 (22)
[23]   Adversarial Attacks for Black-Box Recommender Systems via Copying Transferable Cross-Domain User Profiles [J].
Fan, Wenqi ;
Zhao, Xiangyu ;
Li, Qing ;
Derr, Tyler ;
Ma, Yao ;
Liu, Hui ;
Wang, Jianping ;
Tang, Jiliang .
IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 2023, 35 (12) :12415-12429
[24]   Forensic analysis of AI-compression traces in spatial and frequency domain [J].
Bergmanna, Sandra ;
Moussa, Denise ;
Brand, Fabian ;
Kaup, Andre ;
Riess, Christian .
PATTERN RECOGNITION LETTERS, 2024, 180 :41-47
[25]   Enhancing cross-domain transferability of black-box adversarial attacks on speaker recognition systems using linearized backpropagation [J].
Patel, Umang ;
Bhilare, Shruti ;
Hati, Avik .
PATTERN ANALYSIS AND APPLICATIONS, 2024, 27 (02)
[26]   Adversarial attacks against mouse- and keyboard-based biometric authentication: black-box versus domain-specific techniques [J].
Christian López ;
Jesús Solano ;
Esteban Rivera ;
Lizzy Tengana ;
Johana Florez-Lozano ;
Alejandra Castelblanco ;
Martín Ochoa .
International Journal of Information Security, 2023, 22 :1665-1685
[27]   Adversarial attacks against mouse- and keyboard-based biometric authentication: black-box versus domain-specific techniques [J].
Lopez, Christian ;
Solano, Jesus ;
Rivera, Esteban ;
Tengana, Lizzy ;
Florez-Lozano, Johana ;
Castelblanco, Alejandra ;
Ochoa, Martin .
INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2023, 22 (06) :1665-1685
[28]   Improvement of in-plane spatial resolution of time domain terahertz spectral imaging by application of frequency filter [J].
Fukuchi, T. (fukuchi@criepi.denken.or.jp), 1600, Institute of Electrical Engineers of Japan (133) :146-152
[29]   Learning Orientation Information From Frequency-Domain for Oriented Object Detection in Remote Sensing Images [J].
Zheng, Shangdong ;
Wu, Zebin ;
Xu, Yang ;
Wei, Zhihui ;
Plaza, Antonio .
IEEE TRANSACTIONS ON GEOSCIENCE AND REMOTE SENSING, 2022, 60
[30]   SLf-UNet: Improved UNet for Brain MRI Segmentation by Combining Spatial and Low-Frequency Domain Features [J].
Ding, Hui ;
Lu, Jiacheng ;
Cai, Junwei ;
Zhang, Yawei ;
Shang, Yuanyuan .
ADVANCES IN COMPUTER GRAPHICS, CGI 2023, PT III, 2024, 14497 :415-426