Frequency domain regularization for iterative adversarial attacks

被引:6
|
作者
Li, Tengjiao [1 ]
Li, Maosen [1 ]
Yang, Yanhua [2 ]
Deng, Cheng [1 ]
机构
[1] Xidian Univ, Sch Elect Engn, Xian 710071, Peoples R China
[2] Xidian Univ, Sch Comp Sci & Technol, Xian 710071, Peoples R China
基金
中国国家自然科学基金;
关键词
Adversarial examples; Transfer-based attack; Black-box attack; Frequency-domain characteristics;
D O I
10.1016/j.patcog.2022.109075
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Adversarial examples have attracted more and more attentions with the prosperity of convolutional neural networks. The transferability of adversarial examples is an important property that makes black-box attacks possible in real-world applications. On the other side, many adversarial defense methods have been proposed to improve the robustness, leading to the requirement for more transferable adversarial examples. Inspired by the regularization term for network parameters at training process, we treat adversarial attacks as training process of inputs and propose regularization constraint for inputs to prevent adversarial examples from overfitting the white-box networks and enhance the transferability. Specifically, we find a universal attribute that the outputs of convolutional neural networks have consistency to the low frequencies of inputs, and based on this, we construct a frequency domain regularization to inputs for iterative attacks. In this way, our method is compatible with existing iterative attack methods and can learn more transferable adversarial examples. Extensive experiments on ImageNet validate the superiority of our method, and compared with several attacks, we achieve attack success rate improvements of 8.0% and 11.5% on average to normal models and defense methods respectively. (c) 2022 Published by Elsevier Ltd.
引用
收藏
页数:10
相关论文
共 50 条
  • [1] Frequency-Constrained Iterative Adversarial Attacks for Automatic Modulation Classification
    Chen, Yigong
    Qiao, Xiaoqiang
    Zhang, Jiang
    Zhang, Tao
    Du, Yihang
    IEEE COMMUNICATIONS LETTERS, 2024, 28 (12) : 2734 - 2738
  • [2] Leveraging Information Consistency in Frequency and Spatial Domain for Adversarial Attacks
    Jin, Zhibo
    Zhang, Jiayu
    Zhu, Zhiyu
    Wang, Xinyi
    Huang, Yiyun
    Chen, Huaming
    PRICAI 2024: TRENDS IN ARTIFICIAL INTELLIGENCE, PT I, 2025, 15281 : 93 - 105
  • [3] Pairwise Similarity Regularization for Adversarial Domain Adaptation
    Wang, Haotian
    Yang, Wenjing
    Wang, Ji
    Wang, Ruxin
    Lan, Long
    Geng, Mingyang
    MM '20: PROCEEDINGS OF THE 28TH ACM INTERNATIONAL CONFERENCE ON MULTIMEDIA, 2020, : 2409 - 2418
  • [4] FREQUENCY-DOMAIN ADAPTIVE ITERATIVE IMAGE-RESTORATION AND EVALUATION OF THE REGULARIZATION PARAMETER
    KANG, MG
    KATSKAGGELOS, AK
    OPTICAL ENGINEERING, 1994, 33 (10) : 3222 - 3232
  • [5] Detection of Iterative Adversarial Attacks via Counter Attack
    Rottmann, Matthias
    Maag, Kira
    Peyron, Mathis
    Gottschalk, Hanno
    Krejic, Natasa
    JOURNAL OF OPTIMIZATION THEORY AND APPLICATIONS, 2023, 198 (03) : 892 - 929
  • [6] Detection of Iterative Adversarial Attacks via Counter Attack
    Matthias Rottmann
    Kira Maag
    Mathis Peyron
    Hanno Gottschalk
    Nataša Krejić
    Journal of Optimization Theory and Applications, 2023, 198 : 892 - 929
  • [7] Frequency domain-based reversible adversarial attacks for privacy protection in Internet of Things
    Lu, Yang
    Ma, Tianfeng
    Pang, Zilong
    Chai, Xiuli
    Chen, Zhen
    Tang, Zongwei
    JOURNAL OF ELECTRONIC IMAGING, 2024, 33 (04)
  • [8] Improving DNN Robustness to Adversarial Attacks Using Jacobian Regularization
    Jakubovitz, Daniel
    Girye, Raja
    COMPUTER VISION - ECCV 2018, PT XII, 2018, 11216 : 525 - 541
  • [9] Mel frequency spectral domain defenses against adversarial attacks on speech recognition systems
    Mehlman, Nicholas
    Sreeram, Anirudh
    Peri, Raghuveer
    Narayanan, Shrikanth
    JASA EXPRESS LETTERS, 2023, 3 (03):
  • [10] Transferable Adversarial Attacks on Vision Transformers with Token Gradient Regularization
    Zhang, Jianping
    Huang, Yizhan
    Wu, Weibin
    Lyu, Michael R.
    2023 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2023, : 16415 - 16424