Diffusion Models for Imperceptible and Transferable Adversarial Attack

对抗制 计算机科学 人工智能 扩散 计算机视觉 模式识别(心理学) 热力学 物理
作者
Jianqi Chen,Hao Chen,Keyan Chen,Yilan Zhang,Zhengxia Zou,Zhenwei Shi
出处
期刊:IEEE Transactions on Pattern Analysis and Machine Intelligence [IEEE Computer Society]
卷期号:47 (2): 961-977 被引量:65
标识
DOI:10.1109/tpami.2024.3480519
摘要

Many existing adversarial attacks generate -norm perturbations on image RGB space. Despite some achievements in transferability and attack success rate, the crafted adversarial examples are easily perceived by human eyes. Towards visual imperceptibility, some recent works explore unrestricted attacks without -norm constraints, yet lacking transferability of attacking black-box models. In this work, we propose a novel imperceptible and transferable attack by leveraging both the generative and discriminative power of diffusion models. Specifically, instead of direct manipulation in pixel space, we craft perturbations in the latent space of diffusion models. Combined with well-designed content-preserving structures, we can generate human-insensitive perturbations embedded with semantic clues. For better transferability, we further "deceive" the diffusion model which can be viewed as an implicit recognition surrogate, by distracting its attention away from the target regions. To our knowledge, our proposed method, DiffAttack, is the first that introduces diffusion models into the adversarial attack field. Extensive experiments conducted across diverse model architectures (CNNs, Transformers, and MLPs), datasets (ImageNet, CUB-200, and Standford Cars), and defense mechanisms underscore the superiority of our attack over existing methods such as iterative attacks, GAN-based attacks, and ensemble attacks. Furthermore, we provide a comprehensive discussion on future research avenues in diffusion-based adversarial attacks, aiming to chart a course for this burgeoning field.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
怡然天宇发布了新的文献求助10
刚刚
刚刚
远志发布了新的文献求助10
1秒前
2秒前
lyh完成签到 ,获得积分10
2秒前
3秒前
3秒前
kuiuLinvk完成签到,获得积分10
4秒前
4秒前
科研通AI6.1应助xiaxia采纳,获得10
5秒前
从容水蓝应助小星星采纳,获得10
5秒前
6秒前
语默完成签到 ,获得积分10
6秒前
liian7发布了新的文献求助10
6秒前
erkk发布了新的文献求助30
8秒前
午午午午完成签到 ,获得积分10
8秒前
9秒前
9秒前
123123完成签到,获得积分10
10秒前
12秒前
12秒前
佼佼者发布了新的文献求助30
12秒前
12秒前
13秒前
慕青应助张宋采纳,获得10
13秒前
sswl关注了科研通微信公众号
14秒前
14秒前
淡然的新晴完成签到,获得积分10
16秒前
jiangxiaoyu发布了新的文献求助10
17秒前
上官若男应助45275357采纳,获得30
18秒前
stt发布了新的文献求助10
18秒前
18秒前
18秒前
茄子完成签到 ,获得积分10
19秒前
20秒前
Alioth发布了新的文献求助10
23秒前
23秒前
wanci应助科研通管家采纳,获得10
23秒前
23秒前
arniu2008应助科研通管家采纳,获得20
23秒前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
Picture this! Including first nations fiction picture books in school library collections 2000
The Cambridge History of China: Volume 4, Sui and T'ang China, 589–906 AD, Part Two 1500
Cowries - A Guide to the Gastropod Family Cypraeidae 1200
ON THE THEORY OF BIRATIONAL BLOWING-UP 666
Signals, Systems, and Signal Processing 610
“美军军官队伍建设研究”系列(全册) 500
热门求助领域 (近24小时)
化学 材料科学 医学 生物 纳米技术 工程类 有机化学 化学工程 生物化学 计算机科学 物理 内科学 复合材料 催化作用 物理化学 光电子学 电极 细胞生物学 基因 无机化学
热门帖子
关注 科研通微信公众号,转发送积分 6387713
求助须知:如何正确求助?哪些是违规求助? 8201585
关于积分的说明 17352323
捐赠科研通 5441316
什么是DOI,文献DOI怎么找? 2877509
邀请新用户注册赠送积分活动 1853822
关于科研通互助平台的介绍 1697605