arrow
Return

Reinforcing Adversarial Transferability via Negative Class Guided Example Generation

delete2026-01-01
delete0
PRE
AI
H
Hegui Zhu *
W
Wenqi Cui
Y
Yue Yan
N
Ning Han *
DOI:10.1109/TIFS.2025.3648871delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Recent studies have revealed that Deep Neural Networks (DNNs) are highly vulnerable to adversarial examples, which are generated by introducing imperceptible perturbations to clean images, leading to misclassification. The existing untargeted attack usually only focuses on weakening the original class when generating adversarial examples, ignoring the model's prediction distribution for other classes. Based on the analysis of the attention heatmap of model decision and the existing adversarial attack results, we find that the high-confidence negative classes of the images often reflect the natural weak direction in the model decision, and updating the adversarial examples along this direction is more likely to help it deviate from the original class. Therefore, we propose an untargeted adversarial example generation method via Negative Class Guidance (NCG). First, the logits of the clean image are extracted according to the classification confidence. Second, the soft label is generated via smoothing and normalization operations. Finally, a novel loss function is derived that integrates negative class information with the soft label to guide the update direction of adversarial examples. Extensive experiments conducted on the ImageNet dataset demonstrate that NCG substantially enhances the adversarial transferability of state-of-the-art attack methodologies on both Convolutional Neural Networks (CNNs) and Vision Transformers (ViTs), highlighting its effectiveness in black-box attack scenarios.
Keywords:
Analytical models
Perturbation methods
Sulfur
Computational modeling
Training
Predictive models
Artificial intelligence
Robustness
Mathematical models
Heating systems
Adversarial examples
adversarial transferability
gradient optimization
negative class guidance

Journal

IEEE Transactions on Information Forensics and Security cover
IEEE Transactions on Information Forensics and Security
IF:
8
Papers:
5.2K
Citations:
2.3W

Organization

X
Xiangtan University
Scholars:
1.4K
Papers: 532
Citations: 1.1W
N
northeastern university - china
Scholars:
3.1W
Papers: 2.7W
Citations: 37