Leveraging Spatial Invariance to Boost Adversarial Transferability
Zihan Zhou, Li Li, Yanli Ren, Chuan Qin, Guorui Feng
Abstract
Adversarial examples, crafted with imperceptible perturbations, reveal a significant vulnerability of Deep Neural Networks (DNNs). More critically, the transferability of adversarial examples allows attackers to induce unreasonable predictions without requiring knowledge about the target model. DNNs exhibit spatial invariance, meaning that the position of an object does not affect the classification result. However, existing input transformation-based adversarial attacks solely focus on behavioral patterns at a singular position, failing to fully exploit the spatial invariance exhibited by DNNs across multiple positions, thus constraining the transferability of adversarial examples. To address this, we propose a multi-scale, multi-position input transformationbased attack called Spatial Invariance Diversity (SID). Specifically, SID uses hybrid spatial-spectral fusion mechanisms within localized receptive fields, followed by multiscale spatial downsampling and positional perturbations via random transformations, thereby crafting an ensemble of inputs to activate diverse behavioral patterns of DNNs for effective adversarial perturbations. Extensive experiments on the ImageNet dataset demonstrate that SID could achieve better transferability than the current state-of-theart input transformation-based attacks. Additionally, SID can be flexibly integrated with other input transformationbased or gradient-based attacks, further enhancing the transferability of adversarial examples. The code is available at https://github.com/TheMoss7/SID.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7024b4a1-d9f5-4fa4-8256-c791921600f5Builds on17
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn et al.ICLR 2021 · 21,477 citations
- Fast is better than free: Revisiting adversarial trainingEric Wong, Leslie Rice, J. Zico KolterICLR 2020 · 1,352 citations
- Nesterov Accelerated Gradient and Scale Invariance for Adversarial AttacksJiadong Lin, Chuanbiao Song, Kun He, Liwei Wang et al.ICLR 2020 · 765 citations
- Diffusion Models for Adversarial PurificationWeili Nie, Brandon Guo, Yujia Huang, Chaowei Xiao et al.ICML 2022 · 663 citations
- Admix: Enhancing the Transferability of Adversarial AttacksXiaosen Wang, Xuanran He, Jingdong Wang, Kun HeICCV 2021 · 282 citations
Related papers
- Structure Invariant Transformation for better Adversarial TransferabilityXiaosen Wang, Zeliang Zhang, Jianping ZhangICCV 2023 · 130 citations
- Improving the Transferability of Adversarial Samples With Adversarial TransformationsWeibin Wu, Yuxin Su, Michael R. Lyu, Irwin KingCVPR 2021
- Improving the Transferability of Adversarial Examples with Arbitrary Style TransferZhijin Ge, Fanhua Shang, Hongying Liu, Yuanyuan Liu et al.ACM MM 2023 · 31 citations
- 360-Attack: Distortion-Aware Perturbations from Perspective-ViewsYunjian Zhang, Yanwei Liu, Jinxia Liu, Jingbo Miao et al.CVPR 2022 · 4 citations
- Boosting Adversarial Transferability by Block Shuffle and RotationKunyu Wang, Xuanran He, Wenxuan Wang, Xiaosen WangCVPR 2024 · 61 citations
