IMPROVING ADVERSARIAL TRANSFERABILITY VIA FEATURE TRANSLATION

被引:0
|
作者
Kim, Yoonji [1 ]
Cho, Seungju [1 ]
Byun, Junyoung [1 ]
Kwon, Myung-Joon [1 ]
Kim, Changick [1 ]
机构
[1] Korea Adv Inst Sci & Technol, Sch Elect Engn, Daejeon, South Korea
关键词
Adversarial examples; adversarial attack; transferability; deep neural network;
D O I
10.1109/ICIP49359.2023.10222646
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Deep Neural Networks (DNNs) are vulnerable to adversarial examples, which are crafted to cause the model to make wrong predictions. In real-world scenario, since adversary cannot access to target models, black-box attack has attracted great attention. Among them, many studies have been conducted on transfer-based attacks because they can effectively attack unknown target model. However, transfer-based attacks often fail to fool other models which have slightly different activation maps because adversarial examples tend to overfit to the source model. To alleviate this problem, we introduce Feature Translation Attack (FTA), which applies translation on intermediate features during optimization process. Specifically, FTA generates a new adversarial example whose feature is similar to the ensemble of translated features from the existing adversarial example. We achieved better performance than state-of-the-art methods in extensive experiments.
引用
收藏
页码:3359 / 3363
页数:5
相关论文
共 50 条
  • [31] Boosting the Transferability of Adversarial Samples via Attention
    Wu, Weibin
    Su, Yuxin
    Chen, Xixian
    Zhao, Shenglin
    King, Irwin
    Lyu, Michael R.
    Tai, Yu-Wing
    2020 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2020, : 1158 - 1167
  • [32] Improving adversarial transferability through frequency enhanced momentum
    Zhao, Changfei
    Deng, Xinyang
    Jiang, Wen
    INFORMATION SCIENCES, 2024, 665
  • [33] Improving the Transferability of Adversarial Examples with Arbitrary Style Transfer
    Ge, Zhijin
    Shang, Fanhua
    Liu, Hongying
    Liu, Yuanyuan
    Wan, Liang
    Feng, Wei
    Wang, Xiaosen
    PROCEEDINGS OF THE 31ST ACM INTERNATIONAL CONFERENCE ON MULTIMEDIA, MM 2023, 2023, : 4440 - 4449
  • [34] Adversarial Example Soups: Improving Transferability and Stealthiness for Free
    Yang, Bo
    Zhang, Hengwei
    Wang, Jindong
    Yang, Yulong
    Lin, Chenhao
    Shen, Chao
    Zhao, Zhengyu
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2025, 20 : 1882 - 1894
  • [35] Improving the transferability of adversarial examples through neighborhood attribution
    Ke, Wuping
    Zheng, Desheng
    Li, Xiaoyu
    He, Yuanhang
    Li, Tianyu
    Min, Fan
    KNOWLEDGE-BASED SYSTEMS, 2024, 296
  • [36] GM-Attack: Improving the Transferability of Adversarial Attacks
    Hong, Jinbang
    Tang, Keke
    Gao, Chao
    Wang, Songxin
    Guo, Sensen
    Zhu, Peican
    KNOWLEDGE SCIENCE, ENGINEERING AND MANAGEMENT, KSEM 2022, PT III, 2022, 13370 : 489 - 500
  • [37] Improving Transferability of Adversarial Point Clouds with Model Commonalities
    Lv, Junting
    Liu, Lianguang
    Zhang, Yutong
    Li, Depeng
    Zeng, Zhigang
    2022 IEEE INTERNATIONAL CONFERENCE ON CYBORG AND BIONIC SYSTEMS, CBS, 2022, : 176 - 183
  • [38] Improving the transferability of adversarial examples via the high-level interpretable features for object detection
    Zhiyi Ding
    Lei Sun
    Xiuqing Mao
    Leyu Dai
    Ruiyang Ding
    The Journal of Supercomputing, 81 (6)
  • [39] ENHANCING ADVERSARIAL TRANSFERABILITY IN OBJECT DETECTION WITH BIDIRECTIONAL FEATURE DISTORTION
    Ding, Xinlong
    Chen, Jiansheng
    Yu, Hongwei
    Shang, Yu
    Ma, Huimin
    2024 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH AND SIGNAL PROCESSING, ICASSP 2024, 2024, : 5525 - 5529
  • [40] Improving the transferability of adversarial examples with separable positive and negative disturbances
    Yan, Yuanjie
    Bu, Yuxuan
    Shen, Furao
    Zhao, Jian
    NEURAL COMPUTING & APPLICATIONS, 2024, 36 (07): : 3725 - 3736