Stochastic Universal Adversarial Perturbations with Fixed Optimization Constraint and Ensured High-probability Transferability
Yulin Jin, Xiaoyu Zhang, Haoyu Tong, Jian Lou, Kai Wu, Haibo Hu, Xiaofeng Chen
Abstract
Adversarial perturbations (APs) have become a great concern in image classification tasks. The most challenging branch, universal adversarial perturbations (UAPs), are exploited to fool most of the unseen samples. Such one-to-all perturbations have the merit of transferability, which has strong practical significance. In this paper, we firstly define the transferability gap and the algorithm stability of the UAP algorithm, and prove the relationship between them. In analyzing the UAP algorithm stability, we prove that the convergence domain of existing UAP algorithms with dynamic constraints is excessively small, which degrades the capacity of UAPs. Thus, we further propose a new expected constraint and prove that UAPs in the expected constraint suit any sample in a high probability. Besides, we propose a Stochastic Universal Adversarial Perturbation (SUAP) that involves additive noise and the expected constraint. Finally, by treating the proposed algorithm as a stochastic differential equation, we prove an upper bound of the UAP algorithm stability of SUAP, which decreases exponentially at the beginning and then increases with a sublinear rate to at most a fixed constant. Experimental results show that SUAP is aligned with our analysis. .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 26f13085-5d3d-4aea-914a-fb965a5f48b2Cited by top-tier papers1
Ask how each one uses itBuilds on12
- Universal Adversarial TrainingAli Shafahi, Mahyar Najibi, Zheng Xu, John P. Dickerson et al.AAAI 2020 · 210 citations
- Data-free Universal Adversarial Perturbation and Black-box AttackChaoning Zhang, Philipp Benz, Adil Karjauv, In So KweonICCV 2021 · 83 citations
- Stochastic Gradient and Langevin ProcessesXiang Cheng, Dong Yin, Peter L. Bartlett, Michael I. JordanICML 2020 · 51 citations
- Exploring Non-target Knowledge for Improving Ensemble Universal Adversarial AttacksJuanjuan Weng, Zhiming Luo, Zhun Zhong, Dazhen Lin et al.AAAI 2023 · 24 citations
- MExMI: Pool-based Active Model Extraction Crossover Membership InferenceYaxin Xiao, Qingqing Ye, Haibo Hu, Huadi Zheng et al.NeurIPS 2022 · 17 citations
Related papers
- Robust Universal Adversarial PerturbationsChangming Xu, Gagandeep SinghICML 2024 · 3 citations
- BTUAP: Boosting the Transferability of Universal Adversarial Perturbations in the Black-box Setting under various data dependenciesJie Wan, Jianhao Fu, Ziqi Yang, Kui RenACM MM 2025
- Data-free Universal Adversarial Perturbation with Pseudo-semantic PriorChanhui Lee, Yeonghwan Song, Jeany SonCVPR 2025
- Enhancing Generalization of Universal Adversarial Perturbation through Gradient AggregationXuannan Liu, Yaoyao Zhong, Yuhang Zhang, Lixiong Qin et al.ICCV 2023 · 42 citations
- Improving Generalization of Universal Adversarial Perturbation via Dynamic Maximin OptimizationYechao Zhang, Yingzhe Xu, Junyu Shi, Leo Yu Zhang et al.AAAI 2025 · 7 citations
