Data-free Universal Adversarial Perturbation and Black-box Attack
Chaoning Zhang, Philipp Benz, Adil Karjauv, In So Kweon
Abstract
Universal adversarial perturbation (UAP), i.e. a single perturbation to fool the network for most images, is widely recognized as a more practical attack because the UAP can be generated beforehand and applied directly during the at-tack stage. One intriguing phenomenon regarding untargeted UAP is that most images are misclassified to a dominant label. This phenomenon has been reported in previous works while lacking a justified explanation, for which our work attempts to provide an alternative explanation. For a more practical universal attack, our investigation of untargeted UAP focuses on alleviating the dependence on the original training samples, from removing the need for sample labels to limiting the sample size. Towards strictly data-free untargeted UAP, our work proposes to exploit artificial Jigsaw images as the training samples, demonstrating competitive performance. We further investigate the possibility of exploiting the UAP for a data-free black-box attack which is arguably the most practical yet challenging threat model. We demonstrate that there exists optimization-free repetitive patterns which can successfully attack deep models. Code is available at https://bit.ly/3y0ZTIC.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 38796e46-3598-4609-9183-c004db84daa8Cited by top-tier papers4
- Improving Generalization of Universal Adversarial Perturbation via Dynamic Maximin OptimizationYechao Zhang, Yingzhe Xu, Junyu Shi, Leo Yu Zhang et al.AAAI 2025 · 7 citations
- MADA-Attack: Transferable Multi-modal Attention Distraction Adversarial Attack against Vision Language ModelsZhihan Qin, Jiahao Chen, Chunyi Zhou, Yuwen Pu et al.ICML 2026
- Data-Free Universal Attack by Exploiting the Intrinsic Vulnerability of Deep ModelsYangTian Yan, Jinyu TianAAAI 2025
- Stochastic Universal Adversarial Perturbations with Fixed Optimization Constraint and Ensured High-probability TransferabilityYulin Jin, Xiaoyu Zhang, Haoyu Tong, Jian Lou et al.AAAI 2026
Builds on9
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- HopSkipJumpAttack: A Query-Efficient Decision-Based AttackJianbo Chen, Michael I. Jordan, Martin J. WainwrightS&P 2020 · 797 citations
- Universal Adversarial TrainingAli Shafahi, Mahyar Najibi, Zheng Xu, John P. Dickerson et al.AAAI 2020 · 210 citations
- Universal Perturbation Attack Against Image RetrievalJie Li, Rongrong Ji, Hong Liu, Xiaopeng Hong et al.ICCV 2019 · 115 citations
- Universal Adversarial Perturbation via Prior Driven Uncertainty ApproximationHong Liu, Rongrong Ji, Jie Li, Baochang Zhang et al.ICCV 2019 · 90 citations
Related papers
- Data-free Universal Adversarial Perturbation with Pseudo-semantic PriorChanhui Lee, Yeonghwan Song, Jeany SonCVPR 2025
- Learning Universal Adversarial Perturbation by Adversarial ExampleMaosen Li, Yanhua Yang, Kun Wei, Xu Yang et al.AAAI 2022 · 44 citations
- BTUAP: Boosting the Transferability of Universal Adversarial Perturbations in the Black-box Setting under various data dependenciesJie Wan, Jianhao Fu, Ziqi Yang, Kui RenACM MM 2025
- TRM-UAP: Enhancing the Transferability of Data-Free Universal Adversarial Perturbation via Truncated Ratio MaximizationYiran Liu, Xin Feng, Yunlong Wang, Wu Yang et al.ICCV 2023 · 21 citations
- DarkSAM: Fooling Segment Anything Model to Segment NothingZiqi Zhou, Yufei Song, Minghui Li, Shengshan Hu et al.NeurIPS 2024 · 44 citations
