<p>This paper proposes a method to enhance the transferability of adversarial examples by combining a Learnable Patch-Wise Mask (LPM) generated through differential evolution algorithm with a Feature Importance Aware (FIA) attack. The method learns model-specific regions in images via the differential evolution algorithm and applies a patch-wise mask to discard these regions, guiding the creation of more universal adversarial perturbations. During the feature importance calculation phase, the top-performing ten masks are utilized to process images and aggregate gradients across different strategies, identifying features crucial for model decision-making. These features are then suppressed by optimizing the objective function. Experimental results demonstrate that the combined LPM and FIA method significantly boosts the transferability of adversarial examples, excelling in attacks against unseen models. Furthermore, with the assistance of entropy-weighted aggregation, model boundaries are more clearly defined, further enhancing the attack’s effectiveness.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Block-level masking and feature importance-based adversarial example generation

  • Wenbo Qiu,
  • Yafei Song

摘要

This paper proposes a method to enhance the transferability of adversarial examples by combining a Learnable Patch-Wise Mask (LPM) generated through differential evolution algorithm with a Feature Importance Aware (FIA) attack. The method learns model-specific regions in images via the differential evolution algorithm and applies a patch-wise mask to discard these regions, guiding the creation of more universal adversarial perturbations. During the feature importance calculation phase, the top-performing ten masks are utilized to process images and aggregate gradients across different strategies, identifying features crucial for model decision-making. These features are then suppressed by optimizing the objective function. Experimental results demonstrate that the combined LPM and FIA method significantly boosts the transferability of adversarial examples, excelling in attacks against unseen models. Furthermore, with the assistance of entropy-weighted aggregation, model boundaries are more clearly defined, further enhancing the attack’s effectiveness.