arrow
Return

Adversarial Example Generation Method Based on Wavelet Transform

delete2026-02-10
delete0
delete
OA
AI
M
Meng Bi
X
Xiaoguo Liang
B
Baiyu Wang
L
Longxin Liu
X
Xin Yin
L
Liu, Jiafeng *
DOI:10.3390/info17020182delete
deleteOriginal
deleteShare
deleteSave
View PDF
Abstract

Abstract

En 中文
Adversarial examples are crucial tools for assessing the robustness of deep neural networks (DNNs) and revealing potential security vulnerabilities. Adversarial example generation methods based on Generative Adversarial Networks (GANs) have made significant progress in generating image adversarial examples, but still suffer from insufficient sparsity and transferability. To address these issues, this study proposes a novel semi-white-box untargeted adversarial example generation method named Wavelet-AdvGAN, with an explicit threat model defined as follows. Specifically, the attack is strictly untargeted without predefined target categories, aiming solely to mislead DNNs into classifying adversarial examples into any category other than the original label. It adopts a semi-white-box setting where attackers are denied access to the target model's private information. Regarding the generator's information dependence, the training phase only utilizes public resources (i.e., the target model's public architecture and CIFAR-10 public training data), while the test phase generates adversarial examples through one-step feedforward of clean images without interacting with the target model. The method incorporates a Frequency Sub-band Difference (FSD) module and a Wavelet Transform Local Feature (WTLF) extraction module, evaluating the differences between original and adversarial examples from the frequency domain perspective. This approach constrains the magnitude of perturbations, reinforces feature regions, and further enhances the attack effectiveness, thereby improving the sparsity and transferability of adversarial examples. Experimental results demonstrate that the Wavelet-AdvGAN method achieves an average increase of 1.26% in attack success rates under two defense strategies-data augmentation and adversarial training. Additionally, the adversarial transferability improves by an average of 2.7%. Moreover, the proposed method exhibits a lower l0 norm, indicating better perturbation sparsity. Consequently, it effectively evaluates the robustness of deep neural networks.
Keywords:
wavelet transform
adversarial examples
GAN-based adversarial attacks
attack transferability
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

I
Information
IF:
2.9
Papers:
861
Citations:
9.8K

Organization

S
shenyang university of technology
Scholars:
2.1K
Papers: 683
Citations: 0
Cited Papers

Cited Papers

AdvGAN++: Harnessing Latent Layers for Adversary Generation
err2019-10-01
err0
errOAAI
errSurgan Jandial; Puneet Mangla; Sakshi Varshney; Vineeth Balasubramanian
errShare
errSave
MoE-FFD: Mixture of Experts for Generalized and Parameter-Efficient Face Forgery Detection
err2026-01-01
err0
PREAI
errKong,Chenqi; Luo,Anwei; Bao,Peijun; Yu,Yi; Li,Haoliang; Zheng,Zengwei; Wang,Shiqi; Kot,Alex C.
errShare
errSave
Defense strategies for Adversarial Machine Learning: A survey
err2023-08-01
err13
PREAI
errBountakas, Panagiotis; Zarras, Apostolis; Lekidis, Alexios; Xenakis, Christos
errShare
errSave
CBAM: Convolutional Block Attention Module
err2018-10-06
err0
PREAI
errSanghyun Woo; Jongchan Park; Joon-Young Lee; In So Kweon
errShare
errSave
Toward Model Resistant to Transferable Adversarial Examples via Trigger Activation
err
IF0
err2025-01-01
err0
PREAI
errYi Yu; Song Xia; Xun Lin; Chenqi Kong; Wenhan Yang; Shijian Lu; Yap-Peng Tan; Alex C. Kot
errShare
errSave
Developments in Image Processing Using Deep Learning and Reinforcement Learning
err2023-09-30
err0
errOAAI
errJorge Valente; João António; Carlos Mora; Sandra Jardim
errShare
errSave
Boosting Adversarial Attacks with Momentum
err2018-06-01
err0
errOAAI
errYinpeng Dong; Fangzhou Liao; Tianyu Pang; Hang Su; Jun Zhu; Xiaolin Hu; Jianguo Li
errShare
errSave
researcher View more