Exploring Non-target Knowledge for Improving Ensemble Universal Adversarial Attacks
Juanjuan Weng, Zhiming Luo, Zhun Zhong, Dazhen Lin, Shaozi Li
Abstract
The ensemble attack with average weights can be leveraged for increasing the transferability of universal adversarial perturbation (UAP) by training with multiple Convolutional Neural Networks (CNNs). However, after analyzing the Pearson Correlation Coefficients (PCCs) between the ensemble logits and individual logits of the crafted UAP trained by the ensemble attack, we find that one CNN plays a dominant role during the optimization. Consequently, this average weighted strategy will weaken the contributions of other CNNs and thus limit the transferability for other black-box CNNs. To deal with this bias issue, the primary attempt is to leverage the Kullback-Leibler (KL) divergence loss to encourage the joint contribution from different CNNs, which is still insufficient. After decoupling the KL loss into a target-class part and a non-target-class part, the main issue lies in that the non-target knowledge will be significantly suppressed due to the increasing logit of the target class. In this study, we simply adopt a KL loss that only considers the non-target classes for addressing the dominant bias issue. Besides, to further boost the transferability, we incorporate the min-max learning framework to self-adjust the ensemble weights for each CNN. Experiments results validate that considering the non-target KL loss can achieve superior transferability than the original KL loss by a large margin, and the min-max training can provide a mutual benefit in adversarial ensemble attacks. The source code is available at: https://github.com/WJJLL/ND-MM.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 20c8fc81-4298-4366-9eeb-b98538bc1df4Cited by top-tier papers2
- Stochastic Universal Adversarial Perturbations with Fixed Optimization Constraint and Ensured High-probability TransferabilityYulin Jin, Xiaoyu Zhang, Haoyu Tong, Jian Lou et al.AAAI 2026
- Joint Class-level and Instance-level Relationship Modeling for Novel Class DiscoveryJiaying Zhou, Qingchao ChenAAAI 2025
Builds on10
- AugMix: A Simple Data Processing Method to Improve Robustness and UncertaintyDan Hendrycks, Norman Mu, Ekin Dogus Cubuk, Barret Zoph et al.ICLR 2020 · 1,572 citations
- Do Adversarially Robust ImageNet Models Transfer Better?Hadi Salman, Andrew Ilyas, Logan Engstrom, Ashish Kapoor et al.NeurIPS 2020 · 506 citations
- On Success and Simplicity: A Second Look at Transferable Targeted AttacksZhengyu Zhao, Zhuoran Liu, Martha A. LarsonNeurIPS 2021 · 173 citations
- Stochastic Variance Reduced Ensemble Adversarial Attack for Boosting the Adversarial TransferabilityYifeng Xiong, Jiadong Lin, Min Zhang, John E. Hopcroft et al.CVPR 2022 · 124 citations
- Universal Perturbation Attack Against Image RetrievalJie Li, Rongrong Ji, Hong Liu, Xiaopeng Hong et al.ICCV 2019 · 115 citations
Related papers
- BTUAP: Boosting the Transferability of Universal Adversarial Perturbations in the Black-box Setting under various data dependenciesJie Wan, Jianhao Fu, Ziqi Yang, Kui RenACM MM 2025
- Adversarial Attack Generation Empowered by Min-Max OptimizationJingkang Wang, Tianyun Zhang, Sijia Liu, Pin-Yu Chen et al.NeurIPS 2021 · 49 citations
- Ensemble Diversity Facilitates Adversarial TransferabilityBowen Tang, Zheng Wang, Yi Bin, Qi Dou et al.CVPR 2024 · 22 citations
- TRM-UAP: Enhancing the Transferability of Data-Free Universal Adversarial Perturbation via Truncated Ratio MaximizationYiran Liu, Xin Feng, Yunlong Wang, Wu Yang et al.ICCV 2023 · 21 citations
- Data-free Universal Adversarial Perturbation with Pseudo-semantic PriorChanhui Lee, Yeonghwan Song, Jeany SonCVPR 2025
