<p>Deep neural networks (DNNs) face severe security threats from adversarial examples, particularly transfer-based attacks. Attackers can generate adversarial examples targeting one model to fool multiple other models. Previous works mainly focus on the transferability of untargeted attacks, but it remains a challenge for targeted adversarial attacks. In this paper, we propose a novel method that enables the adversarial example generator to simultaneously learn high-level semantic information and low-level visual information of the target class. In contrast, previous methods only focus on the former. Specifically, we leverage the amplitude spectrum of the target class images to learn the low-level visual information and design an amplitude spectrum alignment mechanism. Meanwhile, we introduce a class-aware balancing module that dynamically adjusts the intensity of amplitude information learning based on the target class, enabling the generator to achieve a balance between learning high-level semantic information and low-level visual information. Extensive experiments on ImageNet demonstrate that our attack method achieves better transferability compared to existing targeted attack methods. For instance, when transferring from Densenet121 to <InlineEquation ID="IEq1"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="530_2025_1915_Article_IEq1.gif" Format="GIF" Height="16" Rendition="HTML" Resolution="72" Type="Linedraw" Width="72" /> </InlineMediaObject> <EquationSource Format="TEX">\(\text {VGG19}_\text {BN}\)</EquationSource> </InlineEquation>, the target fooling rate reaches 68.95%, significantly outperforming other attack methods.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Enhancing transferability of targeted adversarial examples through amplitude spectrum alignment

  • Yaguan Qian,
  • Jiaqiang Sha,
  • Bin Wang,
  • Zhaoquan Gu,
  • Yanchun Zhang

摘要

Deep neural networks (DNNs) face severe security threats from adversarial examples, particularly transfer-based attacks. Attackers can generate adversarial examples targeting one model to fool multiple other models. Previous works mainly focus on the transferability of untargeted attacks, but it remains a challenge for targeted adversarial attacks. In this paper, we propose a novel method that enables the adversarial example generator to simultaneously learn high-level semantic information and low-level visual information of the target class. In contrast, previous methods only focus on the former. Specifically, we leverage the amplitude spectrum of the target class images to learn the low-level visual information and design an amplitude spectrum alignment mechanism. Meanwhile, we introduce a class-aware balancing module that dynamically adjusts the intensity of amplitude information learning based on the target class, enabling the generator to achieve a balance between learning high-level semantic information and low-level visual information. Extensive experiments on ImageNet demonstrate that our attack method achieves better transferability compared to existing targeted attack methods. For instance, when transferring from Densenet121 to \(\text {VGG19}_\text {BN}\) , the target fooling rate reaches 68.95%, significantly outperforming other attack methods.