返回
Improving Transferability of Adversarial Attacks via Frequency-Consistent Regularization
DOI:10.3390/app16083748.png)
摘要
En 中文
对抗样本揭示了深度神经网络的脆弱性,其迁移性使得黑盒攻击尤为令人担忧。然而,在代理模型上精心制作的扰动往往在未见过的目标模型上效果不足。本文从频域视角重新审视这一问题,并观察到扰动优化可能过度依赖特定的频谱模式,从而削弱跨模型迁移能力。为解决该问题,我们提出频谱一致性正则化(FCR),一种简单的插件策略,可与现有迭代攻击结合使用。FCR在每个迭代中引入多个保留低频特征的视图,并随机采样频率范围,随后在这些不同视图中优化扰动。通过这种方式,生成的扰动对特定频谱配置的依赖性降低,表现出更优的迁移性。实验结果表明,FCR能显著提升各类迭代攻击的迁移性能。该改进不仅体现在标准目标模型上,在对抗训练模型中效果更为显著。
Keyword:
adversarial examples
deep neural networks
black-box adversarial attack
transferable attack
iterative attacks
transferability
期刊
A
IF:
2.5
论文数:
7.6K
被引数:
4
机构
引用论文
Inception-v4, Inception-ResNet and the Impact of Residual Connections on LearningInception-v4、Inception-ResNet和剩余连接对学习的影响
Studying the robustness of data imputation methodologies against adversarial attacks研究数据插补方法对抗攻击的鲁棒性
Computers & Security
IF5.4

