paper-with-me

홈 › Papers

Adaptive Image Transformations for Transfer-based Adversarial Attack

2021-11-27 · Zheng Yuan, Jie Zhang, Shiguang Shan

Adversarial attacks provide a good way to study the robustness of deep learning models. One category of methods in transfer-based black-box attack utilizes several image transformation operations to improve the transferability of adversarial examples, which is effective, but fails to take the specific characteristic of the input image into consideration. In this work, we propose a novel architecture, called Adaptive Image Transformation Learner (AITL), which incorporates different image transformation operations into a unified framework to further improve the transferability of adversarial examples. Unlike the fixed combinational transformations used in existing works, our elaborately designed transformation learner adaptively selects the most effective combination of image transformations specific to the input image. Extensive experiments on ImageNet demonstrate that our method significantly improves the attack success rates on both normally trained models and defense models under various settings.

📄 PDF Abstract BibTeX arXiv:2111.13844

Code (2)

huitailangyz/AITL 공식 구현 tf
Trustworthy-AI-Group/TransferAttack pytorch

Tasks

Adversarial Attack

Similar Papers 제목 키워드 기반

An Adaptive Model Ensemble Adversarial Attack for Boosting Adversarial Transferability

2023-08-05 · ICCV 2023 1 · Bin Chen, Jia-Li Yin, Shukai Chen, Bo-Hao Chen 외

While the transferability property of adversarial examples allows the adversary to perform black-box attacks (i.e., the attacker has no knowledge about the target model), the transfer-based adversarial attacks have gaine…

Adversarial Attack

DRIFT: Divergent Response in Filtered Transformations for Robust Adversarial Defense

2025-09-29 · Amira Guesmi, Muhammad Shafique arxiv

Deep neural networks remain highly vulnerable to adversarial examples, and most defenses collapse once gradients can be reliably estimated. We identify \emph{gradient consensus} -- the tendency of randomized transformati…

Adversarial RobustnessAdversarial Defense

Enhancing Tracking Robustness with Auxiliary Adversarial Defense Networks

2024-02-28 · Zhewei Wu, Ruilong Yu, Qihe Liu, Shuying Cheng 외

Adversarial attacks in visual object tracking have significantly degraded the performance of advanced trackers by introducing imperceptible perturbations into images. However, there is still a lack of research on designi…

Adversarial AttackAdversarial DefenseObject TrackingVisual Object Tracking

Improving the Transferability of Adversarial Samples With Adversarial Transformations

2021-06-19 · CVPR 2021 1 · Weibin Wu, Yuxin Su, Michael R. Lyu, Irwin King

Although deep neural networks (DNNs) have achieved tremendous performance in diverse vision challenges, they are surprisingly susceptible to adversarial examples, which are born of intentionally perturbing benign sam…

Admix: Enhancing the Transferability of Adversarial Attacks

2021-01-31 · ICCV 2021 10 · Xiaosen Wang, Xuanran He, Jingdong Wang, Kun He

Deep neural networks are known to be extremely vulnerable to adversarial examples under white-box setting. Moreover, the malicious adversaries crafted on the surrogate (source) model often exhibit black-box transferabili…