Enhancing the Transferability of Adversarial Examples with Random Patch

Yaoyuan Zhang, Yu An Tan, Tian Chen, Xinrui Liu, Quanxin Zhang, Yuanzhang Li*

*此作品的通讯作者

科研成果: 书/报告/会议事项章节会议稿件同行评审

19 引用 (Scopus)

摘要

Adversarial examples can fool deep learning models, and their transferability is critical for attacking black-box models in real-world scenarios. Existing state-of-the-art transferable adversarial attacks tend to exploit intrinsic features of objects to generate adversarial examples. This paper proposes the Random Patch Attack (RPA) to significantly improve the transferability of adversarial examples by the patch-wise random transformation that effectively highlights important intrinsic features of objects. Specifically, we introduce random patch transformations to original images to variate model-specific features. Important object-related features are preserved after aggregating the transformed images since they stay consistent in multiple transformations while model-specific elements are neutralized. The obtained essential features steer noises to perturb the object-related regions, generating the adversarial examples of superior transferability across different models. Extensive experimental results demonstrate the effectiveness of the proposed RPA. Compared to the state-of-the-art transferable attacks, our attacks improve the black-box attack success rate by 2.9% against normally trained models, 4.7% against defense models, and 4.6% against vision transformers on average, reaching a maximum of 99.1%, 93.2%, and 87.8%, respectively.

源语言英语
主期刊名Proceedings of the 31st International Joint Conference on Artificial Intelligence, IJCAI 2022
编辑Luc De Raedt, Luc De Raedt
出版商International Joint Conferences on Artificial Intelligence
1672-1678
页数7
ISBN(电子版)9781956792003
出版状态已出版 - 2022
活动31st International Joint Conference on Artificial Intelligence, IJCAI 2022 - Vienna, 奥地利
期限: 23 7月 202229 7月 2022

出版系列

姓名IJCAI International Joint Conference on Artificial Intelligence
ISSN(印刷版)1045-0823

会议

会议31st International Joint Conference on Artificial Intelligence, IJCAI 2022
国家/地区奥地利
Vienna
时期23/07/2229/07/22

指纹

探究 'Enhancing the Transferability of Adversarial Examples with Random Patch' 的科研主题。它们共同构成独一无二的指纹。

引用此