Enhancing transferability of adversarial examples generated from surrogate models has garnered significant attention in recent research. This property allows these examples to deceive other black-box models. Input augmentation has emerged as a promising approach to improve adversarial transferability, focusing on two aspects: incorporating additional data and transforming the input data itself. However, the first category of approaches, which linearly mix external information, suffers from reduced effectiveness in blending features. On the other hand, the second category of approaches often encounters the issue of gradient redundancy, as they generate very similar inputs across multiple scales. To overcome these challenges, we introduce a novel framework called Uniform Scale and Mix Mask Method (US-MM) for generating adversarial examples. The Mix Mask method refines external information into masks, enabling a nonlinear mixing process. Meanwhile, the Uniform Scale approach explores the boundaries of perturbation using a linear factor, effectively minimizing the negative impact of scale copies. Empirical evaluations on ImageNet ILSVRC 2012 validation set demonstrate that US-MM achieves obviously better transfer attack success rate compared to state-of-the-art methods. Ablation experiments are also conducted to validate the effectiveness of each component in US-MM.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Boosting Adversarial Transferability by Uniform Scale and Mix Mask Method

  • Tao Wang,
  • Qianmu Li,
  • Zhichao Lian,
  • Zijian Ying,
  • Fan Liu,
  • Shunmei Meng

摘要

Enhancing transferability of adversarial examples generated from surrogate models has garnered significant attention in recent research. This property allows these examples to deceive other black-box models. Input augmentation has emerged as a promising approach to improve adversarial transferability, focusing on two aspects: incorporating additional data and transforming the input data itself. However, the first category of approaches, which linearly mix external information, suffers from reduced effectiveness in blending features. On the other hand, the second category of approaches often encounters the issue of gradient redundancy, as they generate very similar inputs across multiple scales. To overcome these challenges, we introduce a novel framework called Uniform Scale and Mix Mask Method (US-MM) for generating adversarial examples. The Mix Mask method refines external information into masks, enabling a nonlinear mixing process. Meanwhile, the Uniform Scale approach explores the boundaries of perturbation using a linear factor, effectively minimizing the negative impact of scale copies. Empirical evaluations on ImageNet ILSVRC 2012 validation set demonstrate that US-MM achieves obviously better transfer attack success rate compared to state-of-the-art methods. Ablation experiments are also conducted to validate the effectiveness of each component in US-MM.