Improving the transferability of adversarial examples through black-box feature attacks

可转让性 黑匣子 对抗制 特征(语言学) 计算机科学 人工智能 模式识别(心理学) 机器学习 语言学 哲学 罗伊特
作者
Maoyuan Wang,Jinwei Wang,Bin Ma,Xiangyang Luo
出处
期刊:Neurocomputing [Elsevier BV]
卷期号:595: 127863-127863 被引量:8
标识
DOI:10.1016/j.neucom.2024.127863
摘要

Deep neural networks (DNNs) are vulnerable and susceptible to imperceptible perturbations. Adversarial examples become more and more popular. Black-box attacks are considered to be the most realistic scenario. Currently, transfer-based black-box attacks show excellent performance. However, transfer-based black-box attacks all require an agent model of the attack, which we call the source model. This leads to the existing transfer-based attacks limited by the features focused on the source model, which creates a bottleneck in improving the transferability of adversarial examples. In order to solve this problem, we propose an attack that mainly targets features that are insensitive to the source model, which we call the black-box feature attack. Specifically, we categorize the features of the image into white-box features and black-box features. The white-box features are source model-sensitive features and the black-box features are source model insensitive features. White-box features are only specific to the source model, while black-box features are more generalized for unknown models. By destroying the image white-box features, the fitted image is obtained and the model intermediate layer feature map is extracted. Afterward, the fitting gradient is found for the fitted images with different fitting degrees. We construct loss functions based on the obtained fitting gradients and feature maps to guide the attacks to better destroy the black-box features of the images. Extensive experiments demonstrate that our methods have higher transferability compared to state-of-the-art methods, which achieve more than 90% of transferability under the normal model. It is also significantly better than other methods on adversarially trained models. Even in the white-box setting, our attack has the best performance.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
更新
PDF的下载单位、IP信息已删除 (2025-6-4)

科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
1秒前
1秒前
2秒前
2秒前
3秒前
3秒前
曾曾完成签到,获得积分10
4秒前
4秒前
雾眠气泡水完成签到,获得积分20
5秒前
7秒前
7秒前
冯宝宝发布了新的文献求助10
8秒前
Wangxiaoyan发布了新的文献求助10
8秒前
8秒前
曾曾发布了新的文献求助10
9秒前
9秒前
qhy发布了新的文献求助10
12秒前
12秒前
包容的世倌完成签到 ,获得积分10
12秒前
13秒前
慕容迎松发布了新的文献求助10
14秒前
乔孟婷完成签到,获得积分10
14秒前
强健的梦蕊完成签到 ,获得积分10
14秒前
15秒前
lyon完成签到 ,获得积分10
15秒前
野原完成签到,获得积分10
15秒前
阿圆发布了新的文献求助10
17秒前
18秒前
思源应助不打烊吗采纳,获得10
19秒前
手拿小铁锤完成签到,获得积分20
20秒前
qingkong完成签到 ,获得积分10
20秒前
TCA循环发布了新的文献求助10
20秒前
Strongly完成签到,获得积分10
20秒前
21秒前
上官若男应助星沉静默采纳,获得10
22秒前
竹筏过海完成签到,获得积分0
22秒前
zihanwang应助射天狼采纳,获得10
23秒前
23秒前
23秒前
魁梧的文轩完成签到 ,获得积分10
25秒前
高分求助中
The Mother of All Tableaux: Order, Equivalence, and Geometry in the Large-scale Structure of Optimality Theory 3000
A new approach to the extrapolation of accelerated life test data 1000
Problems of point-blast theory 400
北师大毕业论文 基于可调谐半导体激光吸收光谱技术泄漏气体检测系统的研究 390
Phylogenetic study of the order Polydesmida (Myriapoda: Diplopoda) 370
Robot-supported joining of reinforcement textiles with one-sided sewing heads 320
Novel Preparation of Chitin Nanocrystals by H2SO4 and H3PO4 Hydrolysis Followed by High-Pressure Water Jet Treatments 300
热门求助领域 (近24小时)
化学 材料科学 医学 生物 工程类 有机化学 生物化学 物理 内科学 纳米技术 计算机科学 化学工程 复合材料 遗传学 基因 物理化学 催化作用 冶金 细胞生物学 免疫学
热门帖子
关注 科研通微信公众号,转发送积分 3998074
求助须知:如何正确求助?哪些是违规求助? 3537636
关于积分的说明 11272063
捐赠科研通 3276726
什么是DOI,文献DOI怎么找? 1807114
邀请新用户注册赠送积分活动 883710
科研通“疑难数据库(出版商)”最低求助积分说明 810007