Towards Transferable Adversarial Attacks with Centralized Perturbation

被引:0
|
作者
Wu, Shangbo [1 ]
Tan, Yu-an [1 ]
Wang, Yajie [1 ]
Ma, Ruinan [1 ]
Ma, Wencong [2 ]
Li, Yuanzhang [2 ]
机构
[1] Beijing Inst Technol, Sch Cyberspace Sci & Technol, Beijing, Peoples R China
[2] Beijing Inst Technol, Sch Comp Sci & Technol, Beijing, Peoples R China
基金
中国国家自然科学基金;
关键词
EXAMPLES;
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Adversarial transferability enables black-box attacks on unknown victim deep neural networks (DNNs), rendering attacks viable in real-world scenarios. Current transferable attacks create adversarial perturbation over the entire image, resulting in excessive noise that overfit the source model. Concentrating perturbation to dominant image regions that are model-agnostic is crucial to improving adversarial efficacy. However, limiting perturbation to local regions in the spatial domain proves inadequate in augmenting transferability. To this end, we propose a transferable adversarial attack with fine-grained perturbation optimization in the frequency domain, creating centralized perturbation. We devise a systematic pipeline to dynamically constrain perturbation optimization to dominant frequency coefficients. The constraint is optimized in parallel at each iteration, ensuring the directional alignment of perturbation optimization with model prediction. Our approach allows us to centralize perturbation towards sample-specific important frequency features, which are shared by DNNs, effectively mitigating source model overfitting. Experiments demonstrate that by dynamically centralizing perturbation on dominating frequency coefficients, crafted adversarial examples exhibit stronger transferability, and allowing them to bypass various defenses.
引用
收藏
页码:6109 / 6116
页数:8
相关论文
共 50 条
  • [1] Towards Transferable Adversarial Attacks on Vision Transformers
    Wei, Zhipeng
    Chen, Jingjing
    Goldblum, Micah
    Wu, Zuxuan
    Goldstein, Tom
    Jiang, Yu-Gang
    THIRTY-SIXTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE / THIRTY-FOURTH CONFERENCE ON INNOVATIVE APPLICATIONS OF ARTIFICIAL INTELLIGENCE / THE TWELVETH SYMPOSIUM ON EDUCATIONAL ADVANCES IN ARTIFICIAL INTELLIGENCE, 2022, : 2668 - 2676
  • [2] Towards Transferable Adversarial Attacks on Image and Video Transformers
    Wei, Zhipeng
    Chen, Jingjing
    Goldblum, Micah
    Wu, Zuxuan
    Goldstein, Tom
    Jiang, Yu-Gang
    Davis, Larry S.
    IEEE TRANSACTIONS ON IMAGE PROCESSING, 2023, 32 : 6346 - 6358
  • [3] AutoMA: Towards Automatic Model Augmentation for Transferable Adversarial Attacks
    Yuan, Haojie
    Chu, Qi
    Zhu, Feng
    Zhao, Rui
    Liu, Bin
    Yu, Nenghai
    IEEE TRANSACTIONS ON MULTIMEDIA, 2023, 25 : 203 - 213
  • [4] Towards transferable adversarial attacks on vision transformers for image classification
    Guo, Xu
    Chen, Peng
    Lu, Zhihui
    Chai, Hongfeng
    Du, Xin
    Wu, Xudong
    JOURNAL OF SYSTEMS ARCHITECTURE, 2024, 152
  • [5] Towards universal and transferable adversarial attacks against network traffic classification
    Ding, Ruiyang
    Sun, Lei
    Zang, Weifei
    Dai, Leyu
    Ding, Zhiyi
    Xu, Bayi
    Computer Networks, 2024, 254
  • [6] Transferable Adversarial Attacks Against ASR
    Gao, Xiaoxue
    Li, Zexin
    Chen, Yiming
    Liu, Cong
    Li, Haizhou
    IEEE SIGNAL PROCESSING LETTERS, 2024, 31 : 2200 - 2204
  • [7] Maxwell’s Demon in MLP-Mixer: towards transferable adversarial attacks
    Haoran Lyu
    Yajie Wang
    Yu-an Tan
    Huipeng Zhou
    Yuhang Zhao
    Quanxin Zhang
    Cybersecurity, 7
  • [8] Maxwell's Demon in MLP-Mixer: towards transferable adversarial attacks
    Lyu, Haoran
    Wang, Yajie
    Tan, Yu-an
    Zhou, Huipeng
    Zhao, Yuhang
    Zhang, Quanxin
    CYBERSECURITY, 2024, 7 (01)
  • [9] ADAPTIVE WARPING NETWORK FOR TRANSFERABLE ADVERSARIAL ATTACKS
    Son, Minji
    Kwon, Myung-Joon
    Kim, Hee-Seon
    Byun, Junyoung
    Cho, Seungju
    Kim, Changick
    2022 IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING, ICIP, 2022, : 3056 - 3060
  • [10] Towards Transferable Targeted Adversarial Examples
    Wang, Zhibo
    Yang, Hongshan
    Feng, Yunhe
    Sun, Peng
    Guo, Hengchang
    Zhang, Zhifei
    Ren, Kui
    2023 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2023, : 20534 - 20543