Enhancing Transferability of Adversarial Examples Through Mixed-Frequency Inputs

被引:1
|
作者
Qian, Yaguan [1 ]
Chen, Kecheng [1 ]
Wang, Bin [2 ]
Gu, Zhaoquan [3 ]
Ji, Shouling [4 ]
Wang, Wei [5 ]
Zhang, Yanchun [6 ,7 ]
机构
[1] Zhejiang Univ Sci & Technol, Sch Big Data Sci, Hangzhou 310023, Peoples R China
[2] Zhejiang Key Lab Artificial Intelligence Things AI, Hangzhou 310053, Peoples R China
[3] Harbin Inst Technol Shenzhen, Sch Comp Sci & Technol, Shenzhen 518071, Peoples R China
[4] Zhejiang Univ, Coll Comp Sci & Technol, Hangzhou 310058, Peoples R China
[5] Xi An Jiao Tong Univ, Minist Educ Key Lab Intelligent Networks & Network, Xian 710049, Peoples R China
[6] Zhejiang Normal Univ, Sch Comp Sci & Technol, Jinhua 321004, Peoples R China
[7] Victoria Univ, Sch Comp Sci & Math, Melbourne, Vic 8001, Australia
基金
中国国家自然科学基金;
关键词
Frequency-domain analysis; Closed box; Noise; Glass box; Training; Optimization; Computational modeling; Security vulnerability; adversarial examples; transfer-based attack; Fourier transform;
D O I
10.1109/TIFS.2024.3430508
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Recent studies have shown that Deep Neural Networks (DNNs) are easily deceived by adversarial examples, revealing their serious vulnerability. Due to the transferability, adversarial examples can attack across multiple models with different architectures, called transfer-based black-box attacks. Input transformation is one of the most effective methods to improve adversarial transferability. In particular, the attacks fusing other categories of image information reveal the potential direction of adversarial attacks. However, the current techniques rely on input transformations in the spatial domain, which ignore the frequency information of the image and limit its transferability. To tackle this issue, we propose Mixed-Frequency Inputs (MFI) based on a frequency domain perspective. MFI alleviates the overfitting of adversarial examples to the source model by considering high-frequency components from various kinds of images in the process of calculating the gradient. By accumulating these high-frequency components, MFI acquires a more steady gradient direction in each iteration, leading to the discovery of better local maxima and enhancing transferability. Extensive experimental results on the ImageNet-compatible datasets demonstrate that MFI outperforms existing transform-based attacks with a clear margin on both Convolutional Neural Networks (CNNs) and Vision Transformers (ViTs), which proves MFI is more suitable for realistic black-box scenarios.
引用
收藏
页码:7633 / 7645
页数:13
相关论文
共 50 条
  • [11] Enhancing transferability of adversarial examples with pixel-level scale variation
    Mao, Zhongshu
    Lu, Yiqin
    Cheng, Zhe
    Shen, Xiong
    SIGNAL PROCESSING-IMAGE COMMUNICATION, 2023, 118
  • [12] Enhancing the Transferability of Adversarial Attacks through Variance Tuning
    Wang, Xiaosen
    He, Kun
    2021 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION, CVPR 2021, 2021, : 1924 - 1933
  • [13] Frequency-based methods for improving the imperceptibility and transferability of adversarial examples
    Zhu, Hegui
    Ren, Yuchen
    Liu, Chong
    Sui, Xiaoyan
    Zhang, Libo
    APPLIED SOFT COMPUTING, 2024, 150
  • [14] An approach to improve transferability of adversarial examples
    Zhang, Weihan
    Guo, Ying
    PHYSICAL COMMUNICATION, 2024, 64
  • [15] Remix: Towards the transferability of adversarial examples
    Zhao, Hongzhi
    Hao, Lingguang
    Hao, Kuangrong
    Wei, Bing
    Cai, Xin
    NEURAL NETWORKS, 2023, 163 : 367 - 378
  • [16] Dynamic defenses and the transferability of adversarial examples
    Thomas, Sam
    Koleini, Farnoosh
    Tabrizi, Nasseh
    2022 IEEE 4TH INTERNATIONAL CONFERENCE ON TRUST, PRIVACY AND SECURITY IN INTELLIGENT SYSTEMS, AND APPLICATIONS, TPS-ISA, 2022, : 276 - 284
  • [17] StyLess: Boosting the Transferability of Adversarial Examples
    Liang, Kaisheng
    Xiao, Bin
    2023 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2023, : 8163 - 8172
  • [18] On the Role of Generalization in Transferability of Adversarial Examples
    Wang, Yilin
    Farnia, Farzan
    UNCERTAINTY IN ARTIFICIAL INTELLIGENCE, 2023, 216 : 2259 - 2270
  • [19] Improving adversarial transferability through frequency enhanced momentum
    Zhao, Changfei
    Deng, Xinyang
    Jiang, Wen
    INFORMATION SCIENCES, 2024, 665
  • [20] ENHANCING THE ADVERSARIAL TRANSFERABILITY OF VISION TRANSFORMERS THROUGH PERTURBATION INVARIANCE
    Zeng Boheng
    2022 19TH INTERNATIONAL COMPUTER CONFERENCE ON WAVELET ACTIVE MEDIA TECHNOLOGY AND INFORMATION PROCESSING (ICCWAMTIP), 2022,