arrow
返回

A Unified Optimization Framework for Feature-Based Transferable Attacks

delete2024-01-01
delete1
PRE
AI
N
Nanqing Xu
W
Weiwei Feng
张
张天柱 (Tianzhu Zhang) *
张
张勇东 (Yongdong Zhang)
DOI:10.1109/TIFS.2024.3380248delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Despite the rapid progress and significant success of deep learning in a wide spectrum of fields, adversarial examples expose many security threats to deep learning models. Recently, an interesting property has been discovered that adversarial examples are transferable, which means adversarial examples targeting a given model can also attack another model. Therefore, many researchers are attracted by this property and work on how to improve the transferability of adversarial examples. Furthermore, compared to the traditional attack methods of disrupting output logits (dubbed logit-based attacks), recent works reveal that disrupting feature maps instead of logits can lead to more transferable adversarial examples (dubbed feature-based attacks). However, previous feature-based attacks mostly hold the intuitive designs of the optimization goals and specialization for certain scenarios with a lack of theoretical motivations and a unified framework. To overcome these limitations, we propose a Unified Feature-based Attack Framework, dubbed as UFAF, combining a dispersion loss and a distance loss, which unifies eight existing feature-based attacks. Furthermore, we also bridge the formulation gap between feature-based attacks and traditional logit-based attacks. With our UFAF, we propose an Entropy-Wasserstein (EW) attack by specifying the dispersion loss as Entropy and the distance loss as Wasserstein Distance, respectively. Besides, we provide theoretical analysis to guarantee the effectiveness of the proposed attack method. Extensive experimental results show the superior performance of our EW attack, which can outperform state-of-the-art attacks by 4.95% on attack success rates in untargeted attack settings, and by 1.95% on targeted transfer rates and 1.17% on target success rates in targeted attack settings. Moreover, our framework can help other feature-based attacks improve their performance by 7.7% in untargeted attack settings.
Keyword:
Adversarial attacks
untargeted attacks
targeted attack
transferable attacks
unified framework

期刊

IEEE Transactions on Information Forensics and Security 封面图
IEEE Transactions on Information Forensics and Security
IF:
8
论文数:
5.3K
被引数:
2.3W

机构

U
university of science & technology of china, cas
学者数:
3.2W
论文数: 2.7W
被引数: 74
C
chinese academy of sciences
学者数:
56.7W
论文数: 45.0W
被引数: 704
引用论文

引用论文

err分享
err收藏
Efficacy of dalbavancin against MRSA biofilms in a rat model of orthopaedic implant-associated infection
err2020-05-17
err0
errOAAI
errVanessa Silva; H Sofia Antão; João Guimarães; Justina Prada; Isabel Pires; Ângela Martins; Luís Maltez; José E Pereira; José L Capelo; Gilberto Igrejas; Patrícia Poeta
err分享
err收藏
err分享
err收藏
学者 查看更多内容