Enhancing Transferability of Adversarial Examples with Spatial Momentum

被引:8
|
作者
Wang, Guoqiu [1 ]
Yan, Huanqian [1 ]
Wei, Xingxing [2 ]
机构
[1] Beihang Univ, Beijing Key Lab Digital Media DML, Sch Comp Sci & Engn, Beijing, Peoples R China
[2] Beihang Univ, Inst Artificial Intelligence, Hangzhou Innovat Inst, Beijing, Peoples R China
基金
中国国家自然科学基金; 国家重点研发计划;
关键词
Adversarial attack; Adversarial transferability; Momentum-based attack;
D O I
10.1007/978-3-031-18907-4_46
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Many adversarial attack methods achieve satisfactory attack success rates under the white-box setting, but they usually show poor transferability when attacking other DNN models. Momentum-based attack is one effective method to improve transferability. It integrates the momentum term into the iterative process, which can stabilize the update directions by adding the gradients' temporal correlation for each pixel. We argue that only this temporal momentum is not enough, the gradients from the spatial domain within an image, i.e. gradients from the context pixels centered on the target pixel are also important to the stabilization. For that, we propose a novel method named Spatial Momentum Iterative FGSM attack (SMI-FGSM), which introduces the mechanism of momentum accumulation from temporal domain to spatial domain by considering the context information from different regions within the image. SMI-FGSM is then integrated with temporal momentum to simultaneously stabilize the gradients' update direction from both the temporal and spatial domains. Extensive experiments show that our method indeed further enhances adversarial transferability. It achieves the best transferability success rate for multiple mainstream undefended and defended models, which outperforms the state-of-the-art attack methods by a large margin of 10% on average.
引用
收藏
页码:593 / 604
页数:12
相关论文
共 50 条
  • [41] Enhancing the Transferability of Adversarial Patch via Alternating Minimization
    Wang, Yang
    Chen, Lei
    Yang, Zhen
    Cao, Tieyong
    INTERNATIONAL JOURNAL OF COMPUTATIONAL INTELLIGENCE SYSTEMS, 2024, 17 (01)
  • [42] Enhancing the Transferability of Adversarial Attacks through Variance Tuning
    Wang, Xiaosen
    He, Kun
    2021 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION, CVPR 2021, 2021, : 1924 - 1933
  • [43] Improving Transferability of Adversarial Attacks with Gaussian Gradient Enhance Momentum
    Wang, Jinwei
    Wang, Maoyuan
    Wu, Hao
    Ma, Bin
    Luo, Xiangyang
    PATTERN RECOGNITION AND COMPUTER VISION, PRCV 2023, PT IX, 2024, 14433 : 421 - 432
  • [44] Enhancing Adversarial Example Transferability with an Intermediate Level Attack
    Huang, Qian
    Katsman, Isay
    He, Horace
    Gu, Zeqi
    Belongie, Serge
    Lim, Ser-Nam
    2019 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2019), 2019, : 4732 - 4741
  • [45] Enhancing Adversarial Transferability via Information Bottleneck Constraints
    Qi, Biqing
    Gao, Junqi
    Liu, Jianxing
    Wu, Ligang
    Zhou, Bowen
    IEEE SIGNAL PROCESSING LETTERS, 2024, 31 : 1414 - 1418
  • [46] Enhancing the transferability of adversarial attacks with diversified input strategies
    Li Z.
    Chen Y.
    Yang B.
    Li C.
    Zhang S.
    Li W.
    Zhang H.
    Journal of Intelligent and Fuzzy Systems, 2024, 46 (04): : 10359 - 10373
  • [47] Enhancing adversarial transferability with partial blocks on vision transformer
    Yanyang Han
    Ju Liu
    Xiaoxi Liu
    Xiao Jiang
    Lingchen Gu
    Xuesong Gao
    Weiqiang Chen
    Neural Computing and Applications, 2022, 34 : 20249 - 20262
  • [48] Strengthening transferability of adversarial examples by adaptive inertia and amplitude spectrum dropout
    Li, Huanhuan
    Yu, Wenbo
    Huang, He
    NEURAL NETWORKS, 2023, 165 : 925 - 937
  • [49] Boosting Transferability of Targeted Adversarial Examples via Hierarchical Generative Networks
    Yang, Xiao
    Dong, Yinpeng
    Pang, Tianyu
    Su, Hang
    Zhu, Jun
    COMPUTER VISION - ECCV 2022, PT IV, 2022, 13664 : 725 - 742
  • [50] ON THE TRANSFERABILITY OF ADVERSARIAL EXAMPLES AGAINST CNN-BASED IMAGE FORENSICS
    Barni, M.
    Kallas, K.
    Nowroozi, E.
    Tondi, B.
    2019 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH AND SIGNAL PROCESSING (ICASSP), 2019, : 8286 - 8290