Sparse and Imperceptible Adversarial Attack via a Homotopy Algorithm
Mingkang Zhu, Tianlong Chen, Zhangyang Wang
Abstract
Sparse adversarial attacks can fool deep neural networks (DNNs) by only perturbing a few pixels (regularized by l_0 norm). Recent efforts combine it with another l_infty imperceptible on the perturbation magnitudes. The resultant sparse and imperceptible attacks are practically relevant, and indicate an even higher vulnerability of DNNs that we usually imagined. However, such attacks are more challenging to generate due to the optimization difficulty by coupling the l_0 regularizer and box constraints with a non-convex objective. In this paper, we address this challenge by proposing a homotopy algorithm, to jointly tackle the sparsity and the perturbation bound in one unified framework. Each iteration, the main step of our algorithm is to optimize an l_0-regularized adversarial loss, by leveraging the nonmonotone Accelerated Proximal Gradient Method (nmAPG) for nonconvex programming; it is followed by an l_0 change control step, and an optional post-attack step designed to escape bad local minima. We also extend the algorithm to handling the structural sparsity regularizer. We extensively examine the effectiveness of our proposed homotopy attack for both targeted and non-targeted attack scenarios, on CIFAR-10 and ImageNet datasets. Compared to state-of-the-art methods, our homotopy attack leads to significantly fewer perturbations, e.g., reducing 42.91% on CIFAR-10 and 75.03% on ImageNet (average case, targeted attack), at similar maximal perturbation magnitudes, when still achieving 100% attack success rates. Our codes are available at: https://github.com/VITA-Group/SparseADV_Homotopy.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 69d47841-a21f-4359-b76d-22e76d39fa5aCited by top-tier papers6
- Brusleattack: a Query-Efficient Score- based Black-Box Sparse Adversarial AttackViet Quoc Vo, Ehsan Abbasnejad, Damith RanasingheICLR 2024 · 14 citations
- Transferable Structural Sparse Adversarial Attack Via Exact Group Sparsity TrainingDi Ming, Peng Ren, Yunlong Wang, Xin FengCVPR 2024 · 7 citations
- Web Artifact Attacks Disrupt Vision Language ModelsMaan Qraitem, Piotr Teterwak, Kate Saenko, Bryan A. PlummerICCV 2025 · 4 citations
- Vpr-Cloak: a First Look at Privacy Cloak Against Visual Place RecognitionShuting Dong, Mingzhi Chen, Feng Lu, Hao Yu et al.ICCV 2025 · 2 citations
- Black-Box Sparse Adversarial Attack via Multi-Objective Optimisation CVPR ProceedingsPhoenix Neale Williams, Ke LiCVPR 2023
Builds on7
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Attacks Which Do Not Kill Training Make Adversarial Learning StrongerJingfeng Zhang, Xilie Xu, Bo Han, Gang Niu et al.ICML 2020 · 452 citations
- Geometry-aware Instance-reweighted Adversarial TrainingJingfeng Zhang, Jianing Zhu, Gang Niu, Bo Han et al.ICLR 2021 · 316 citations
- Sparse and Imperceivable Adversarial AttacksFrancesco Croce, Matthias HeinICCV 2019 · 228 citations
- GreedyFool: Distortion-Aware Sparse Adversarial AttackXiaoyi Dong, Dongdong Chen, Jianmin Bao, Chuan Qin et al.NeurIPS 2020 · 87 citations
Related papers
- GSE: Group-wise Sparse and Explainable Adversarial AttacksShpresim Sadiku, Moritz Wagner, Sebastian PokuttaICLR 2025
- σ-zero: Gradient-based Optimization of ℓ0-norm Adversarial ExamplesAntonio Emanuele Cinà, Francesco Villani, Maura Pintor, Lea Schönherr et al.ICLR 2025
- Towards Efficient Training and Evaluation of Robust Models against l0 Bounded Adversarial PerturbationsXuyang Zhong, Yixiao Huang, Chen LiuICML 2024 · 3 citations
- Understanding and Improving Fast Adversarial Training against Bounded PerturbationsXuyang Zhong, Yixiao Huang, Chen LiuNeurIPS 2025
- Improving Adversarial Robustness by Putting More Regularizations on Less Robust SamplesDongyoon Yang, Insung Kong, Yongdai KimICML 2023 · 15 citations
