IMPROVING ADVERSARIAL TRANSFERABILITY VIA FEATURE TRANSLATION

被引:0
|
作者
Kim, Yoonji [1 ]
Cho, Seungju [1 ]
Byun, Junyoung [1 ]
Kwon, Myung-Joon [1 ]
Kim, Changick [1 ]
机构
[1] Korea Adv Inst Sci & Technol, Sch Elect Engn, Daejeon, South Korea
关键词
Adversarial examples; adversarial attack; transferability; deep neural network;
D O I
10.1109/ICIP49359.2023.10222646
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Deep Neural Networks (DNNs) are vulnerable to adversarial examples, which are crafted to cause the model to make wrong predictions. In real-world scenario, since adversary cannot access to target models, black-box attack has attracted great attention. Among them, many studies have been conducted on transfer-based attacks because they can effectively attack unknown target model. However, transfer-based attacks often fail to fool other models which have slightly different activation maps because adversarial examples tend to overfit to the source model. To alleviate this problem, we introduce Feature Translation Attack (FTA), which applies translation on intermediate features during optimization process. Specifically, FTA generates a new adversarial example whose feature is similar to the ensemble of translated features from the existing adversarial example. We achieved better performance than state-of-the-art methods in extensive experiments.
引用
收藏
页码:3359 / 3363
页数:5
相关论文
共 50 条
  • [1] Improving Transferability of Universal Adversarial Perturbation With Feature Disruption
    Wang, Donghua
    Yao, Wen
    Jiang, Tingsong
    Chen, Xiaoqian
    IEEE TRANSACTIONS ON IMAGE PROCESSING, 2024, 33 : 722 - 737
  • [2] Improving Adversarial Transferability via Model Alignment
    Ma, Avery
    Farahmand, Amir-Massoud
    Pan, Yangchen
    Torr, Philip
    Gu, Jindong
    COMPUTER VISION - ECCV 2024, PT LXII, 2025, 15120 : 74 - 92
  • [3] Improving the transferability of adversarial examples via direction tuning
    Yang, Xiangyuan
    Lin, Jie
    Zhang, Hanlin
    Yang, Xinyu
    Zhao, Peng
    INFORMATION SCIENCES, 2023, 647
  • [4] Boosting the Transferability of Video Adversarial Examples via Temporal Translation
    Wei, Zhipeng
    Chen, Jingjing
    Wu, Zuxuan
    Jiang, Yu-Gang
    THIRTY-SIXTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE / THIRTY-FOURTH CONFERENCE ON INNOVATIVE APPLICATIONS OF ARTIFICIAL INTELLIGENCE / THE TWELVETH SYMPOSIUM ON EDUCATIONAL ADVANCES IN ARTIFICIAL INTELLIGENCE, 2022, : 2659 - 2667
  • [5] Improving Transferability of Adversarial Samples via Critical Region-Oriented Feature-Level Attack
    Li, Zhiwei
    Ren, Min
    Li, Qi
    Jiang, Fangling
    Sun, Zhenan
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 6650 - 6664
  • [6] Improving the transferability of adversarial attacks via self-ensemble
    Cheng, Shuyan
    Li, Peng
    Liu, Jianguo
    Xu, He
    Yao, Yudong
    APPLIED INTELLIGENCE, 2024, 54 (21) : 10608 - 10626
  • [7] Improving the Transferability of Adversarial Samples with Adversarial Transformations
    Wu, Weibin
    Su, Yuxin
    Lyu, Michael R.
    King, Irwin
    2021 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION, CVPR 2021, 2021, : 9020 - 9029
  • [8] Boosting Adversarial Transferability via Logits Mixup With Dominant Decomposed Feature
    Weng, Juanjuan
    Luo, Zhiming
    Li, Shaozi
    Lin, Dazhen
    Zhong, Zhun
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 8939 - 8951
  • [9] Enhancing the Transferability of Adversarial Attacks via Multi-Feature Attention
    Zheng, Desheng
    Ke, Wuping
    Li, Xiaoyu
    Duan, Yaoxin
    Yin, Guangqiang
    Min, Fan
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2025, 20 : 1462 - 1474
  • [10] Improving the Transferability of Adversarial Attacks on Face Recognition With Beneficial Perturbation Feature Augmentation
    Zhou, Fengfan
    Ling, Hefei
    Shi, Yuxuan
    Chen, Jiazhong
    Li, Zongyi
    Li, Ping
    IEEE TRANSACTIONS ON COMPUTATIONAL SOCIAL SYSTEMS, 2023, 11 (06) : 1 - 13