Towards Transferable Adversarial Attacks with Centralized Perturbation

被引:0
|
作者
Wu, Shangbo [1 ]
Tan, Yu-an [1 ]
Wang, Yajie [1 ]
Ma, Ruinan [1 ]
Ma, Wencong [2 ]
Li, Yuanzhang [2 ]
机构
[1] Beijing Inst Technol, Sch Cyberspace Sci & Technol, Beijing, Peoples R China
[2] Beijing Inst Technol, Sch Comp Sci & Technol, Beijing, Peoples R China
基金
中国国家自然科学基金;
关键词
EXAMPLES;
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Adversarial transferability enables black-box attacks on unknown victim deep neural networks (DNNs), rendering attacks viable in real-world scenarios. Current transferable attacks create adversarial perturbation over the entire image, resulting in excessive noise that overfit the source model. Concentrating perturbation to dominant image regions that are model-agnostic is crucial to improving adversarial efficacy. However, limiting perturbation to local regions in the spatial domain proves inadequate in augmenting transferability. To this end, we propose a transferable adversarial attack with fine-grained perturbation optimization in the frequency domain, creating centralized perturbation. We devise a systematic pipeline to dynamically constrain perturbation optimization to dominant frequency coefficients. The constraint is optimized in parallel at each iteration, ensuring the directional alignment of perturbation optimization with model prediction. Our approach allows us to centralize perturbation towards sample-specific important frequency features, which are shared by DNNs, effectively mitigating source model overfitting. Experiments demonstrate that by dynamically centralizing perturbation on dominating frequency coefficients, crafted adversarial examples exhibit stronger transferability, and allowing them to bypass various defenses.
引用
收藏
页码:6109 / 6116
页数:8
相关论文
共 50 条
  • [21] Transferable Adversarial Attacks on Vision Transformers with Token Gradient Regularization
    Zhang, Jianping
    Huang, Yizhan
    Wu, Weibin
    Lyu, Michael R.
    2023 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2023, : 16415 - 16424
  • [22] Prompt-Driven Contrastive Learning for Transferable Adversarial Attacks
    Yang, Hunmin
    Jeong, Jongoh
    Yoon, Kuk-Jin
    COMPUTER VISION-ECCV 2024, PT XLIII, 2025, 15101 : 36 - 53
  • [23] Perturbation analysis of gradient -based adversarial attacks
    Ozbulak, Utku
    Gasparyan, Manvel
    De Neve, Wesley
    Van Messem, Arnout
    PATTERN RECOGNITION LETTERS, 2020, 135 : 313 - 320
  • [24] ATTA: Adversarial Task -transferable Attacks on Autonomous Driving Systems
    Hang, Qingjie
    Hang, Maosen
    Qiu, Han
    Hang, Tianwei
    Msahli, Mounira
    Memmi, Gerard
    23RD IEEE INTERNATIONAL CONFERENCE ON DATA MINING, ICDM 2023, 2023, : 798 - 807
  • [25] DIVERSE GENERATIVE PERTURBATIONS ON ATTENTION SPACE FOR TRANSFERABLE ADVERSARIAL ATTACKS
    Kim, Woo Jae
    Hong, Seunghoon
    Yoon, Sung-Eui
    2022 IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING, ICIP, 2022, : 281 - 285
  • [26] Towards Transferable Adversarial Examples Using Meta Learning
    Fan, Mingyuan
    Yin, Jia-Li
    Liu, Ximeng
    Guo, Wenzhong
    ALGORITHMS AND ARCHITECTURES FOR PARALLEL PROCESSING, ICA3PP 2021, PT I, 2022, 13155 : 178 - 192
  • [27] Towards Transferable Unrestricted Adversarial Examples with Minimum Changes
    Liu, Fangcheng
    Zhang, Chao
    Zhang, Hongyang
    2023 IEEE CONFERENCE ON SECURE AND TRUSTWORTHY MACHINE LEARNING, SATML, 2023, : 327 - 338
  • [28] Structure Matters: Towards Generating Transferable Adversarial Images
    Peng, Dan
    Zheng, Zizhan
    Luo, Linhao
    Zhang, Xiaofeng
    ECAI 2020: 24TH EUROPEAN CONFERENCE ON ARTIFICIAL INTELLIGENCE, 2020, 325 : 1419 - 1426
  • [29] Towards Understanding the Dynamics of Adversarial Attacks
    Ji, Yujie
    Wang, Ting
    PROCEEDINGS OF THE 2018 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (CCS'18), 2018, : 2228 - 2230
  • [30] Exploring transferable and robust adversarial perturbation generation across network hierarchy
    Wang, Ruikui
    Guo, Yuanfang
    Yang, Ruijie
    Wang, Yunhong
    NEUROCOMPUTING, 2024, 610