IMPROVING ADVERSARIAL TRANSFERABILITY VIA FEATURE TRANSLATION

被引:0
|
作者
Kim, Yoonji [1 ]
Cho, Seungju [1 ]
Byun, Junyoung [1 ]
Kwon, Myung-Joon [1 ]
Kim, Changick [1 ]
机构
[1] Korea Adv Inst Sci & Technol, Sch Elect Engn, Daejeon, South Korea
关键词
Adversarial examples; adversarial attack; transferability; deep neural network;
D O I
10.1109/ICIP49359.2023.10222646
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Deep Neural Networks (DNNs) are vulnerable to adversarial examples, which are crafted to cause the model to make wrong predictions. In real-world scenario, since adversary cannot access to target models, black-box attack has attracted great attention. Among them, many studies have been conducted on transfer-based attacks because they can effectively attack unknown target model. However, transfer-based attacks often fail to fool other models which have slightly different activation maps because adversarial examples tend to overfit to the source model. To alleviate this problem, we introduce Feature Translation Attack (FTA), which applies translation on intermediate features during optimization process. Specifically, FTA generates a new adversarial example whose feature is similar to the ensemble of translated features from the existing adversarial example. We achieved better performance than state-of-the-art methods in extensive experiments.
引用
收藏
页码:3359 / 3363
页数:5
相关论文
共 50 条
  • [41] FDT: Improving the transferability of adversarial examples with frequency domain transformation
    Ling, Jie
    Chen, Jinhui
    Li, Honglei
    COMPUTERS & SECURITY, 2024, 144
  • [42] Improving the Adversarial Transferability of Vision Transformers with Virtual Dense Connection
    Zhang, Jianping
    Huang, Yizhan
    Xu, Zhuoer
    Wu, Weibin
    Lyu, Michael R.
    THIRTY-EIGHTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, VOL 38 NO 7, 2024, : 7133 - 7141
  • [43] Improving the Transferability of Adversarial Samples by Path-Augmented Method
    Zhang, Jianping
    Huang, Jen-tse
    Wang, Wenxuan
    Li, Yichen
    Wu, Weibin
    Wang, Xiaosen
    Sue, Yuxin
    Lyu, Michael R.
    2023 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2023, : 8173 - 8182
  • [44] Improving the transferability of adversarial examples with separable positive and negative disturbances
    Yuanjie Yan
    Yuxuan Bu
    Furao Shen
    Jian Zhao
    Neural Computing and Applications, 2024, 36 : 3725 - 3736
  • [45] IMPROVING VISUAL QUALITY AND TRANSFERABILITY OF ADVERSARIAL ATTACKS ON FACE RECOGNITION SIMULTANEOUSLY WITH ADVERSARIAL RESTORATION
    Zhou, Fengfan
    Ling, Hefei
    Shi, Yuxuan
    Chen, Jiazhong
    Li, Ping
    2024 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH AND SIGNAL PROCESSING, ICASSP 2024, 2024, : 4540 - 4544
  • [46] Improving Transferability of Adversarial Patches on Face Recognition with Generative Models
    Xiao, Zihao
    Gao, Xianfeng
    Fu, Chilin
    Dong, Yinpeng
    Gao, Wei
    Zhang, Xiaolu
    Zhou, Jun
    Zhu, Jun
    2021 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION, CVPR 2021, 2021, : 11840 - 11849
  • [47] Improving Transferability of Adversarial Attacks with Gaussian Gradient Enhance Momentum
    Wang, Jinwei
    Wang, Maoyuan
    Wu, Hao
    Ma, Bin
    Luo, Xiangyang
    PATTERN RECOGNITION AND COMPUTER VISION, PRCV 2023, PT IX, 2024, 14433 : 421 - 432
  • [48] Improving transferability of adversarial examples by saliency distribution and data augmentation
    Dong, Yansong
    Tang, Long
    Tian, Cong
    Yu, Bin
    Duan, Zhenhua
    COMPUTERS & SECURITY, 2022, 120
  • [49] Enhancing the Transferability of Adversarial Patch via Alternating Minimization
    Wang, Yang
    Chen, Lei
    Yang, Zhen
    Cao, Tieyong
    INTERNATIONAL JOURNAL OF COMPUTATIONAL INTELLIGENCE SYSTEMS, 2024, 17 (01)
  • [50] Enhancing Adversarial Transferability via Information Bottleneck Constraints
    Qi, Biqing
    Gao, Junqi
    Liu, Jianxing
    Wu, Ligang
    Zhou, Bowen
    IEEE SIGNAL PROCESSING LETTERS, 2024, 31 : 1414 - 1418