Adversarial examples are effective at deceiving deep neural network models for which they are specifically crafted and also demonstrate transferability across different models. This characteristic facilitates attacks in black-box scenarios, where the internal workings of the victim models are inaccessible. The Intermediate-Level Attack (ILA) enhances transferability by guiding the direction of the generation of perturbations using intermediate-level outputs. However, ILA struggles with transferring examples between models with different architectures, such as from Convolutional Neural Networks (CNNs) to Vision Transformers (ViTs). To address this, we introduce the Ensemble of Intermediate-Level Attacks (EILA). This approach leverages intermediate outputs from multiple source models to more effectively guide perturbation directions in the generation of adversarial examples. By adopting a shared guidance adversarial example strategy, EILA reduces conflicts in perturbation directions across different models, thereby enhancing overall transfer performance. Experimental results reveal significant enhancements in the transferability of adversarial examples across a range of deep learning models, demonstrating the effectiveness of EILA.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Ensemble of Intermediate-Level Attacks to Boost Adversarial Transferability

  • Yunce Zhao,
  • Wei Huang,
  • Wei Liu,
  • Xin Yao

摘要

Adversarial examples are effective at deceiving deep neural network models for which they are specifically crafted and also demonstrate transferability across different models. This characteristic facilitates attacks in black-box scenarios, where the internal workings of the victim models are inaccessible. The Intermediate-Level Attack (ILA) enhances transferability by guiding the direction of the generation of perturbations using intermediate-level outputs. However, ILA struggles with transferring examples between models with different architectures, such as from Convolutional Neural Networks (CNNs) to Vision Transformers (ViTs). To address this, we introduce the Ensemble of Intermediate-Level Attacks (EILA). This approach leverages intermediate outputs from multiple source models to more effectively guide perturbation directions in the generation of adversarial examples. By adopting a shared guidance adversarial example strategy, EILA reduces conflicts in perturbation directions across different models, thereby enhancing overall transfer performance. Experimental results reveal significant enhancements in the transferability of adversarial examples across a range of deep learning models, demonstrating the effectiveness of EILA.