Ensemble Diversity Facilitates Adversarial Transferability

被引:0
|
作者
Tang, Bowen [1 ]
Wang, Zheng [1 ,2 ]
Bin, Yi [1 ]
Dou, Qi [3 ]
Yang, Yang [1 ]
Shen, Heng Tao [1 ]
机构
[1] Univ Elect Sci & Technol China, Chengdu, Peoples R China
[2] UESTC, Inst Elect & Informat Engn, Guangzhou, Guangdong, Peoples R China
[3] Chinese Univ Hong Kong, Hong Kong, Peoples R China
关键词
D O I
10.1109/CVPR52733.2024.02301
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
With the advent of ensemble-based attacks, the transfer-ability of generated adversarial examples is elevated by a noticeable margin despite many methods only employing superficial integration yet ignoring the diversity between ensemble models. However, most of them compromise the latent value of the diversity between generated perturbation from distinct models which we argue is also able to increase the adversarial transferability, especially heterogeneous at-tacks. To address the issues, we propose a novel method of Stochastic Mini-batch black-box attack with Ensemble Reweighing using reinforcement learning (SMER) to produce highly transferable adversarial examples. We emphasize the diversity between surrogate models achieving indi-vidual perturbation iteratively. In order to customize the individual effect between surrogates, ensemble reweighing is introduced to refine ensemble weights by maximizing attack loss based on reinforcement learning which functions on the ultimate transferability elevation. Extensive exper-iments demonstrate our superiority to recent ensemble at-tacks with a significant margin across different black-box attack scenarios, especially on heterogeneous conditions. https://github.com/tangbwb/SMER
引用
收藏
页码:24377 / 24386
页数:10
相关论文
共 50 条
  • [21] Dynamic defenses and the transferability of adversarial examples
    Thomas, Sam
    Koleini, Farnoosh
    Tabrizi, Nasseh
    2022 IEEE 4TH INTERNATIONAL CONFERENCE ON TRUST, PRIVACY AND SECURITY IN INTELLIGENT SYSTEMS, AND APPLICATIONS, TPS-ISA, 2022, : 276 - 284
  • [22] Rethinking the Backward Propagation for Adversarial Transferability
    Wang, Xiaosen
    Tong, Kangheng
    He, Kun
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 36 (NEURIPS 2023), 2023,
  • [23] Enhancing the Adversarial Transferability with Channel Decomposition
    Lin B.
    Gao F.
    Zeng W.
    Chen J.
    Zhang C.
    Zhu Q.
    Zhou Y.
    Zheng D.
    Qiu Q.
    Yang S.
    Computer Systems Science and Engineering, 2023, 46 (03): : 3075 - 3085
  • [24] StyLess: Boosting the Transferability of Adversarial Examples
    Liang, Kaisheng
    Xiao, Bin
    2023 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2023, : 8163 - 8172
  • [25] A Geometric Perspective on the Transferability of Adversarial Directions
    Charles, Zachary
    Rosenberg, Harrison
    Papailiopoulos, Dimitris
    22ND INTERNATIONAL CONFERENCE ON ARTIFICIAL INTELLIGENCE AND STATISTICS, VOL 89, 2019, 89
  • [26] Admix: Enhancing the Transferability of Adversarial Attacks
    Wang, Xiaosen
    He, Xuanran
    Wang, Jingdong
    He, Kun
    2021 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2021), 2021, : 16138 - 16147
  • [27] Backpropagation Path Search On Adversarial Transferability
    Xu, Zhuoer
    Gu, Zhangxuan
    Zhang, Jianping
    Cui, Shiwen
    Meng, Changhua
    Wang, Weiqiang
    2023 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION, ICCV, 2023, : 4640 - 4650
  • [28] Randomized Purifier Based on Low Adversarial Transferability for Adversarial Defense
    Park, Sangjin
    Jung, Yoojin
    Song, Byung Cheol
    IEEE ACCESS, 2024, 12 : 109690 - 109701
  • [29] Enhancing adversarial transferability with local transformation
    Zhang, Yang
    Hong, Jinbang
    Bai, Qing
    Liang, Haifeng
    Zhu, Peican
    Song, Qun
    COMPLEX & INTELLIGENT SYSTEMS, 2025, 11 (01)
  • [30] Transferability of Quantum Adversarial Machine Learning
    Li, Vincent
    Wooldridge, Tyler
    Wang, Xiaodi
    PROCEEDINGS OF SEVENTH INTERNATIONAL CONGRESS ON INFORMATION AND COMMUNICATION TECHNOLOGY, ICICT 2022, VOL. 2, 2023, 448 : 805 - 814