Improving adversarial transferability through hybrid augmentation

可转让性 计算机科学 对抗制 领域(数学分析) 光学(聚焦) 遮罩(插图) 人工智能 多样性(政治) 缩放比例 频域 图像(数学) 机器学习 模式识别(心理学) 算法 计算机视觉 数学 几何学 光学 物理 数学分析 罗伊特 艺术 社会学 视觉艺术 人类学
作者
Peican Zhu,Zepeng Fan,Sensen Guo,Keke Tang,Xingyu Li
出处
期刊:Computers & Security [Elsevier BV]
卷期号:139: 103674-103674 被引量:8
标识
DOI:10.1016/j.cose.2023.103674
摘要

Many works have shown that the adversarial examples being generated on a known substitute model have the ability to mislead other unknown black-box models, which has attracted widespread attention. Recently, many model augmentation methods have been presented to boost the corresponding transferability of adversarial examples by transforming the images to simulate diverse models for attack. However, existing model augmentation methods focus on the transformations in a single domain and may restrict the diversity of simulated models. To overcome this limitation, we present a novel model augmentation method named Hybrid Augmentation Method (HAM). Our approach comprises two components, channel-wise scaling (CS) and spectrum masking (SM). Specifically, we first transform the images with CS in the spatial domain, which enhances the diversity of transformed images by randomly scaling the channel. Then we apply SM to randomly remove some frequency information of the images in the frequency domain, further increasing the diversity of the transformed images. Instead of confining the transformations in a single domain, we take transformations both in the spatial and frequency domain simultaneously. This enables us to get more various transformed images and largely increases the diversity of simulated models to create more powerful adversarial examples. We conduct extensive experiments to demonstrate the superiority of our method on both undefended and defense models, which largely outperforms the considered attacks. Moreover, our method can be integrated with other attacks to further enhance the adversarial transferability.

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
吕科伟发布了新的文献求助10
1秒前
1秒前
大猫完成签到,获得积分10
1秒前
1秒前
1秒前
天空发布了新的文献求助10
2秒前
allen完成签到,获得积分10
3秒前
4秒前
brick完成签到,获得积分10
4秒前
4秒前
4秒前
月yue发布了新的文献求助10
5秒前
汉堡包应助冯利采纳,获得10
5秒前
勤恳万宝路完成签到,获得积分10
5秒前
秋熙宸完成签到,获得积分10
6秒前
小蘑菇应助姚驰采纳,获得10
6秒前
7秒前
在水一方应助斑马兽采纳,获得10
7秒前
Ava应助斑马兽采纳,获得10
7秒前
李健的粉丝团团长应助Li采纳,获得10
7秒前
7秒前
jjyy发布了新的文献求助10
8秒前
PGM发布了新的文献求助10
8秒前
略略略发布了新的文献求助10
8秒前
蓝榆完成签到,获得积分10
9秒前
大模型应助brick采纳,获得10
9秒前
ZeKaWa应助小高采纳,获得10
9秒前
renshiq完成签到,获得积分10
11秒前
jiulin发布了新的文献求助10
11秒前
冷静伟诚完成签到,获得积分10
12秒前
略略略完成签到,获得积分10
13秒前
QDL完成签到,获得积分10
13秒前
淡定的海雪完成签到 ,获得积分20
14秒前
小二郎应助李木槿采纳,获得10
15秒前
jiulin完成签到,获得积分10
15秒前
怡然凡柔完成签到,获得积分10
15秒前
bhcs发布了新的文献求助30
15秒前
神勇的绿凝完成签到,获得积分10
16秒前
16秒前
17秒前
高分求助中
Overcoming Stigma and Bias in Obesity Management 1200
Signals, Systems, and Signal Processing 610
Software that combines deep learning,3D reconstruction and CFD to analyze the state of carotid arteries from ultrasound imaging 500
Bounds for Statistical Estimation in Semiparametric Models 500
Forced degradation and stability indicating LC method for Letrozole: A stress testing guide 500
Ideology and Meaning-Making under the Putin Regime 450
Adhesion Science: Principles & Practice 400
热门求助领域 (近24小时)
化学 材料科学 医学 生物 纳米技术 工程类 有机化学 化学工程 生物化学 计算机科学 物理 内科学 复合材料 催化作用 物理化学 光电子学 电极 细胞生物学 基因 无机化学
热门帖子
关注 科研通微信公众号,转发送积分 6492681
求助须知:如何正确求助?哪些是违规求助? 8290272
关于积分的说明 17690439
捐赠科研通 5584589
什么是DOI,文献DOI怎么找? 2915411
邀请新用户注册赠送积分活动 1892511
关于科研通互助平台的介绍 1750705