arrow
返回

Improving adversarial transferability through hybrid augmentation

delete2024-04-01
delete4
PRE
AI
P
Peican Zhu
S
Sensen Guo
K
Keke Tang *
X
Xingyu Li *
DOI:10.1016/j.cose.2023.103674delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Many works have shown that the adversarial examples being generated on a known substitute model have the ability to mislead other unknown black-box models, which has attracted widespread attention. Recently, many model augmentation methods have been presented to boost the corresponding transferability of adversarial examples by transforming the images to simulate diverse models for attack. However, existing model augmentation methods focus on the transformations in a single domain and may restrict the diversity of simulated models. To overcome this limitation, we present a novel model augmentation method named Hybrid Augmentation Method (HAM). Our approach comprises two components, channel-wise scaling (CS) and spectrum masking (SM). Specifically, we first transform the images with CS in the spatial domain, which enhances the diversity of transformed images by randomly scaling the channel. Then we apply SM to randomly remove some frequency information of the images in the frequency domain, further increasing the diversity of the transformed images. Instead of confining the transformations in a single domain, we take transformations both in the spatial and frequency domain simultaneously. This enables us to get more various transformed images and largely increases the diversity of simulated models to create more powerful adversarial examples. We conduct extensive experiments to demonstrate the superiority of our method on both undefended and defense models, which largely outperforms the considered attacks. Moreover, our method can be integrated with other attacks to further enhance the adversarial transferability.
Keyword:
Deep neural networks
Adversarial examples
Transfer-based attacks
Model augmentation
Adversarial transferability

期刊

C
Computers and Security
IF:
5.4
论文数:
4.6K
被引数:
1.4W

机构

U
university of alberta
学者数:
5.1W
论文数: 4.9W
被引数: 65
G
Guangzhou University
学者数:
1.8W
论文数: 1.3W
被引数: 1.8W
N
Northwestern Polytechnical University
学者数:
4.6W
论文数: 3.7W
被引数: 5.3W
学者 查看更多机构
引用论文

引用论文

Improving transferability of adversarial examples by saliency distribution and data augmentation
err2022-09-01
err4
PREAI
errDong, Yansong; Tang, Long; Tian, Cong; Yu, Bin; Duan, Zhenhua
err分享
err收藏
End-to-end lung cancer screening with three-dimensional deep learning on low-dose chest computed tomography基于低剂量胸部ct的三维深度学习端到端肺癌筛查
err2019-05-20
err1.1K
PREAI
errArdila, Diego; Kiraly, Atilla P.; Bharadwaj, Sujeeth; Choi, Bokyung; Reicher, Joshua J.; Peng, Lily; Tse, Daniel; Etemadi, Mozziyar; Ye, Wenxing; Corrado, Greg; Naidich, David P.; Shetty, Shravya
err分享
err收藏
ImageNet Large Scale Visual Recognition ChallengeImageNet大规模视觉识别挑战
err2015-04-11
err2.7W
PREAI
errRussakovsky, Olga; Deng, Jia; Su, Hao; Krause, Jonathan; Satheesh, Sanjeev; Ma, Sean; Huang, Zhiheng; Karpathy, Andrej; Khosla, Aditya; Bernstein, Michael; Berg, Alexander C.; Fei-Fei, Li
err分享
err收藏
err分享
err收藏