On the Convergence of an Adaptive Momentum Method for Adversarial Attacks
Sheng Long, Wei Tao, Shuohao Li, Jun Lei, Jun Zhang
Abstract
Adversarial examples are commonly created by solving a constrained optimization problem, typically using sign-based methods like Fast Gradient Sign Method (FGSM). These attacks can benefit from momentum with a constant parameter, such as Momentum Iterative FGSM (MI-FGSM), to enhance black-box transferability. However, the monotonic time-varying momentum parameter is required to guarantee convergence in theory, creating a theory-practice gap. Additionally, recent work shows that sign-based methods fail to converge to the optimum in several convex settings, exacerbating the issue. To address these concerns, we propose a novel method which incorporates both an innovative adaptive momentum parameter without monotonicity assumptions and an adaptive step-size scheme that replaces the sign operation. Furthermore, we derive a regret upper bound for general convex functions. Experiments on multiple models demonstrate the efficacy of our method in generating adversarial examples with human-imperceptible noise while achieving high attack success rates, indicating its superiority over previous adversarial example generation methods.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers1
Ask how each one uses itBuilds on14
- Searching for MobileNetV3Andrew Howard, Ruoming Pang, Hartwig Adam, Quoc V. Le et al.ICCV 2019 · 9,163 citations
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- Nesterov Accelerated Gradient and Scale Invariance for Adversarial AttacksJiadong Lin, Chuanbiao Song, Kun He, Liwei Wang et al.ICLR 2020 · 765 citations
- Symbolic Discovery of Optimization AlgorithmsXiangning Chen, Chen Liang, Da Huang, Esteban Real et al.NeurIPS 2023 · 734 citations
- AdaBelief Optimizer: Adapting Stepsizes by the Belief in Observed GradientsJuntang Zhuang, Tommy Tang, Yifan Ding, Sekhar Tatikonda et al.NeurIPS 2020 · 697 citations
Related papers
- The Power of Decaying Steps: Enhancing Attack Stability and Transferability for Sign-based OptimizersWei Tao, Yang Dai, Jincai Huang, Qing TaoCVPR 2026
- Enhancing Adversarial Transferability by Balancing Exploration and Exploitation with Gradient-Guided SamplingZenghao Niu, Weicheng Xie, Siyang Song, Zitong Yu et al.ICCV 2025 · 2 citations
- Making Adversarial Examples More Transferable and IndistinguishableJunhua Zou, Yexin Duan, Boyu Li, Wu Zhang et al.AAAI 2022 · 42 citations
- Towards Transferable Targeted AttackMaosen Li, Cheng Deng, Tengjiao Li, Junchi Yan et al.CVPR 2020
- Transferable Adversarial Attack for Both Vision Transformers and Convolutional Networks via Momentum Integrated GradientsWenshuo Ma, Yidong Li, Xiaofeng Jia, Wei XuICCV 2023 · 62 citations
