Feature Importance-aware Transferable Adversarial Attacks
Zhibo Wang, Hengchang Guo, Zhifei Zhang, Wenxin Liu, Zhan Qin, Kui Ren
Abstract
Transferability of adversarial examples is of central importance for attacking an unknown model, which facilitates adversarial attacks in more practical scenarios, e.g., black-box attacks. Existing transferable attacks tend to craft adversarial examples by indiscriminately distorting features to degrade prediction accuracy in a source model without aware of intrinsic features of objects in the images. We argue that such brute-force degradation would introduce model-specific local optimum into adversarial examples, thus limiting the transferability. By contrast, we propose the Feature Importance-aware Attack (FIA), which disrupts important object-aware features that dominate model decisions consistently. More specifically, we obtain feature importance by introducing the aggregate gradient, which averages the gradients with respect to feature maps of the source model, computed on a batch of random transforms of the original clean image. The gradients will be highly correlated to objects of interest, and such correlation presents invariance across different models. Besides, the random transforms will preserve intrinsic features of objects and suppress model-specific information. Finally, the feature importance guides to search for adversarial examples to-wards disrupting critical features, achieving stronger transferability. Extensive experimental evaluation demonstrates the effectiveness and superior performance of the proposed FIA, i.e., improving the success rate by 9.5% against normally trained models and 12.8% against defense models as compared to the state-of-the-art transferable attacks. Code is available at: https://github.com/hcguoO0/FIA
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers56
- Improving Adversarial Transferability via Neuron Attribution-based AttacksJianping Zhang, Weibin Wu, Jen-tse Huang, Yizhan Huang et al.CVPR 2022 · 140 citations
- An Adaptive Model Ensemble Adversarial Attack for Boosting Adversarial TransferabilityBin Chen, Jia-Li Yin, Shukai Chen, Bohao Chen et al.ICCV 2023 · 96 citations
- Natural Color Fool: Towards Boosting Black-box Unrestricted AttacksShengming Yuan, Qilong Zhang, Lianli Gao, Yaya Cheng et al.NeurIPS 2022 · 86 citations
- Boosting Adversarial Transferability by Block Shuffle and RotationKunyu Wang, Xuanran He, Wenxuan Wang, Xiaosen WangCVPR 2024 · 61 citations
- Generating Transferable 3D Adversarial Point Cloud via Random Perturbation FactorizationBangyan He, Jian Liu, Yiming Li, Siyuan Liang et al.AAAI 2023 · 53 citations
Builds on6
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Nesterov Accelerated Gradient and Scale Invariance for Adversarial AttacksJiadong Lin, Chuanbiao Song, Kun He, Liwei Wang et al.ICLR 2020 · 765 citations
- Enhancing Adversarial Example Transferability With an Intermediate Level AttackQian Huang, Isay Katsman, Zeqi Gu, Horace He et al.ICCV 2019 · 293 citations
- FDA: Feature Disruptive AttackAditya Ganeshan, Vivek B. S., Venkatesh Babu RadhakrishnanICCV 2019 · 136 citations
- Transferable Perturbations of Deep Feature DistributionsNathan Inkawhich, Kevin J. Liang, Lawrence Carin, Yiran ChenICLR 2020 · 100 citations
Related papers
- Pixel2Feature Attack (P2FA): Rethinking the Perturbed Space to Enhance Adversarial TransferabilityRenpu Liu, Hao Wu, Jiawei Zhang, Xin Cheng et al.ICML 2025
- Focus on Generalization: Improving Adversarial Transferability via Bi-Level Bias MitigationYiqiang Guo, Lei Zhong, Bin Chen, Jia-Li Yin et al.ACM MM 2025
- Transferable Adversarial Attack based on Integrated GradientsYi Huang, Adams Wai-Kin KongICLR 2022 · 75 citations
- Towards Transferable Targeted Adversarial ExamplesZhibo Wang, Hongshan Yang, Yunhe Feng, Peng Sun et al.CVPR 2023
- Towards Transferable Adversarial Attacks with Centralized PerturbationShangbo Wu, Yu-an Tan, Yajie Wang, Ruinan Ma et al.AAAI 2024 · 15 citations
