paper-with-me

Papers

Frequency-Domain Regularized Adversarial Alignment for Transferable Attacks against Closed-Source MLLMs

2026-05-20 · Leitao Yuan, Qinghua Mao, Daizong Liu, Kun Wang, Wenjie Wang, Yan Teng, Jing Shao, Dongrui Liu arxiv

Multimodal large language models (MLLMs) remain vulnerable to transfer-based targeted attacks, where perturbations optimized on open-source surrogate encoders can generalize to closed-source MLLMs. A key challenge for improving adversarial transferability is to effectively capture the intrinsic visual focus shared across different models, such that perturbations align with transferable semantic cues rather than surrogate-specific behaviors. However, existing methods suffer from spatial-domain feature redundancy and surrogate-specific gradient signals, thereby hindering cross-model transferability. In this paper, we propose FRA-Attack, which addresses both challenges from a unified frequency-domain regularization perspective. For feature alignment, a high-pass DCT objective on patch features suppresses redundant global structures and concentrates the loss on the high-frequency band that carries the MLLMs' intrinsic visual focus. For gradient optimization, we introduce Frequency-domain Gradient Regularization (FGR), a \textit{model-agnostic} low-pass regularizer that modulates the surrogate gradient using only the geometric frequency coordinate, \textit{i.e.}, no surrogate-derived statistic is involved, so that FGR is model-agnostic by construction, removing surrogate-specific high-frequency artifacts while preserving transferable low-frequency directions. Together, the two components form a unified frequency-domain treatment of transferability. Extensive experiments on $15$ flagship MLLMs across $7$ vendors show that FRA-Attack achieves superior cross-model transferability, particularly with state-of-the-art performance on GPT-5.4, Claude-Opus-4.6 and Gemini-3-flash.

📄 PDF Abstract BibTeX arXiv:2605.21541

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

Towards Transferable Adversarial Attacks with Centralized Perturbation

2023-12-11 · Shangbo Wu, Yu-an Tan, Yajie Wang, Ruinan Ma 외

Adversarial transferability enables black-box attacks on unknown victim deep neural networks (DNNs), rendering attacks viable in real-world scenarios. Current transferable attacks create adversarial perturbation over the…

Adversarial Attack

FreqAlign: Excavating Perception-oriented Transferability for Blind Image Quality Assessment from A Frequency Perspective

2023-09-29 · Xin Li, Yiting Lu, Zhibo Chen

Blind Image Quality Assessment (BIQA) is susceptible to poor transferability when the distribution shift occurs, e.g., from synthesis degradation to authentic degradation. To mitigate this, some studies have attempted to…

Blind Image Quality AssessmentDomain AdaptationImage Quality AssessmentUnsupervised Domain Adaptation

FACL-Attack: Frequency-Aware Contrastive Learning for Transferable Adversarial Attacks

2024-07-30 · Hunmin Yang, Jongoh Jeong, Kuk-Jin Yoon

Deep neural networks are known to be vulnerable to security risks due to the inherent transferable nature of adversarial examples. Despite the success of recent generative model-based attacks demonstrating strong transfe…

Contrastive Learning

Frequency-based Automated Modulation Classification in the Presence of Adversaries

2020-11-02 · Rajeev Sahay, Christopher G. Brinton, David J. Love

Automatic modulation classification (AMC) aims to improve the efficiency of crowded radio spectrums by automatically predicting the modulation constellation of wireless RF signals. Recent work has demonstrated the abilit…

ClassificationDeep LearningGeneral Classification

Dual Mixup Regularized Learning for Adversarial Domain Adaptation

2020-07-07 · ECCV 2020 8 · Yuan Wu, Diana Inkpen, Ahmed El-Roby

Recent advances on unsupervised domain adaptation (UDA) rely on adversarial learning to disentangle the explanatory and transferable features for domain adaptation. However, there are two issues with the existing methods…

Domain AdaptationUnsupervised Domain Adaptation