Foolmix: Strengthen the Transferability of Adversarial Examples by Dual-Blending and Direction Update Strategy

可转让性 对抗制 计算机科学 对偶(语法数字) 人工智能 机器学习 艺术 文学类 罗伊特
作者
Zhankai Li,Weiping Wang,Jie Li,Kai Chen,Shigeng Zhang
出处
期刊:IEEE Transactions on Information Forensics and Security [Institute of Electrical and Electronics Engineers]
卷期号:19: 5286-5300 被引量:5
标识
DOI:10.1109/tifs.2024.3393745
摘要

Adversarial example attacks are deemed to be a serious threat to deep neural network (DNN) models. Generating adversarial examples in white-box settings has been well-studied, however, it remains challenging to generate transferable adversarial examples that successfully attack black-box models. This work proposes Foolmix, a novel method for generating transferable adversarial examples for black-box attacks. The design of Foolmix is inspired by our observation that adversarial examples with high transferability usually carry multi-class features in the latent space of DNN models. Thus, we propose a dual-blending strategy that blends the image with a set of random pixel-blocks and blends the gradient by calculating the loss of the blended image for both the ground-truth label and a set of random labels. The dual-blending strategy pressures the example to penetrate multiple class regions and gain multi-class features in the latent space, greatly enhancing the transferability of the generated adversarial example. However, the randomness in the blending process might also pressure the example to approach the boundary of the original class region, which lowers the robustness of the example. To mitigate this problem, we further propose an update method in the starting forward direction to guide the generated adversarial example to go deep into multi-class adversarial regions while being globally far away from the original class region. Compared to state-of-the-art transformation-based attacks, Foolmix significantly enhances the transferability of generated adversarial examples, boosting the average transferable attack success rate by 13.2% and 16.9% on mainstream CNNs and ViTs respectively, while achieving better defense breakthrough ability.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
晨丶完成签到,获得积分10
刚刚
优秀的老鼠完成签到,获得积分10
3秒前
小明完成签到,获得积分10
4秒前
Zsy完成签到,获得积分10
6秒前
Lincoln完成签到,获得积分10
7秒前
塘仔完成签到,获得积分10
7秒前
LZNUDT发布了新的文献求助10
8秒前
杨杨杨完成签到 ,获得积分10
10秒前
橙橙完成签到 ,获得积分10
10秒前
曹广秀完成签到,获得积分10
11秒前
小张医生完成签到,获得积分10
16秒前
酷炫映阳完成签到 ,获得积分10
16秒前
cdercder应助luckweb采纳,获得10
17秒前
hy1234完成签到 ,获得积分0
17秒前
小拳头完成签到,获得积分10
18秒前
qn完成签到,获得积分10
18秒前
所所应助zhaomr采纳,获得10
19秒前
shiyi完成签到,获得积分10
20秒前
迷人绿柏完成签到 ,获得积分10
20秒前
zjh完成签到,获得积分10
23秒前
晓风完成签到,获得积分0
23秒前
PEIfq完成签到 ,获得积分10
23秒前
沉默的瑞宝完成签到 ,获得积分10
23秒前
时尚中二完成签到,获得积分10
24秒前
星星完成签到 ,获得积分10
24秒前
所所应助科研通管家采纳,获得30
24秒前
Owen应助科研通管家采纳,获得10
25秒前
Kao应助科研通管家采纳,获得10
25秒前
cdercder应助科研通管家采纳,获得10
25秒前
fengwei应助科研通管家采纳,获得10
25秒前
共享精神应助科研通管家采纳,获得30
25秒前
cdercder应助科研通管家采纳,获得10
25秒前
JamesPei应助科研通管家采纳,获得10
26秒前
超超完成签到 ,获得积分10
26秒前
26秒前
26秒前
jun完成签到,获得积分10
28秒前
NatureLee完成签到 ,获得积分10
28秒前
展仕波完成签到,获得积分10
29秒前
天晴完成签到,获得积分10
29秒前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
China Pluperfect I: Epistemology of Past and Outside in Chinese Art 520
Matrix Methods in Data Mining and Pattern Recognition Second Edition 510
Cosmos as Art Object: Studies in Plato's Timaeus and Other Dialogues 500
What is the Future of Psychotherapy in Digital Age? Technology, AI Bots, and Psychotherapy after Covid 444
Management and the Arts 310
Teaching Social and Emotional Learning in Physical Education 300
热门求助领域 (近24小时)
化学 材料科学 医学 生物 纳米技术 工程类 有机化学 化学工程 生物化学 计算机科学 内科学 物理 复合材料 催化作用 细胞生物学 无机化学 光电子学 物理化学 电极 基因
热门帖子
关注 科研通微信公众号,转发送积分 7634461
求助须知:如何正确求助?哪些是违规求助? 9208519
关于积分的说明 19748527
捐赠科研通 7202624
什么是DOI,文献DOI怎么找? 3275054
关于科研通互助平台的介绍 2436953
邀请新用户注册赠送积分活动 2271959