arrow
Return

A Unified Optimization Framework for Feature-Based Transferable Attacks

delete2024-01-01
delete1
PRE
AI
N
Nanqing Xu
W
Weiwei Feng
张
张天柱 (Tianzhu Zhang) *
张
张勇东 (Yongdong Zhang)
DOI:10.1109/TIFS.2024.3380248delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Despite the rapid progress and significant success of deep learning in a wide spectrum of fields, adversarial examples expose many security threats to deep learning models. Recently, an interesting property has been discovered that adversarial examples are transferable, which means adversarial examples targeting a given model can also attack another model. Therefore, many researchers are attracted by this property and work on how to improve the transferability of adversarial examples. Furthermore, compared to the traditional attack methods of disrupting output logits (dubbed logit-based attacks), recent works reveal that disrupting feature maps instead of logits can lead to more transferable adversarial examples (dubbed feature-based attacks). However, previous feature-based attacks mostly hold the intuitive designs of the optimization goals and specialization for certain scenarios with a lack of theoretical motivations and a unified framework. To overcome these limitations, we propose a Unified Feature-based Attack Framework, dubbed as UFAF, combining a dispersion loss and a distance loss, which unifies eight existing feature-based attacks. Furthermore, we also bridge the formulation gap between feature-based attacks and traditional logit-based attacks. With our UFAF, we propose an Entropy-Wasserstein (EW) attack by specifying the dispersion loss as Entropy and the distance loss as Wasserstein Distance, respectively. Besides, we provide theoretical analysis to guarantee the effectiveness of the proposed attack method. Extensive experimental results show the superior performance of our EW attack, which can outperform state-of-the-art attacks by 4.95% on attack success rates in untargeted attack settings, and by 1.95% on targeted transfer rates and 1.17% on target success rates in targeted attack settings. Moreover, our framework can help other feature-based attacks improve their performance by 7.7% in untargeted attack settings.
Keywords:
Adversarial attacks
untargeted attacks
targeted attack
transferable attacks
unified framework

Journal

IEEE Transactions on Information Forensics and Security cover
IEEE Transactions on Information Forensics and Security
IF:
8
Papers:
5.3K
Citations:
2.3W

Organization

U
university of science & technology of china, cas
Scholars:
3.2W
Papers: 2.7W
Citations: 74
C
chinese academy of sciences
Scholars:
56.7W
Papers: 45.0W
Citations: 704
Cited Papers

Cited Papers

Efficacy of dalbavancin against MRSA biofilms in a rat model of orthopaedic implant-associated infection
err2020-05-17
err0
errOAAI
errVanessa Silva; H Sofia Antão; João Guimarães; Justina Prada; Isabel Pires; Ângela Martins; Luís Maltez; José E Pereira; José L Capelo; Gilberto Igrejas; Patrícia Poeta
errShare
errSave
Computational Optimal Transport
err2019-01-01
err1.6K
PREAI
errPeyre, Gabriel; Cuturi, Marco
errShare
errSave
Robust and Generalized Physical Adversarial Attacks via Meta-GAN
err2024-01-01
err11
PREAI
errFeng, Weiwei; Xu, Nanqing; Zhang, Tianzhu; Wu, Baoyuan; Zhang, Yongdong
errShare
errSave
The use of facial motion and facial form during the processing of identity
err2003-08-01
err0
PREAI
errBarbara Knappmeyer; Ian M Thornton; Heinrich H Bülthoff
errShare
errSave
researcher View more