ALA: Naturalness-aware Adversarial Lightness Attack
Yihao Huang, Liangru Sun, Qing Guo, Felix Juefei-Xu, Jiayi Zhu, Jincao Feng, Yang Liu, Geguang Pu
Abstract
Most researchers have tried to enhance the robustness of deep neural networks (DNNs) by revealing and repairing the vulnerability of DNNs with specialized adversarial examples. Parts of the attack examples have imperceptible perturbations restricted by Lp norm. However, due to their high-frequency property, the adversarial examples can be defended by denoising methods and are hard to realize in the physical world. To avoid the defects, some works have proposed unrestricted attacks to gain better robustness and practicality. It is disappointing that these examples usually look unnatural and can alert the guards. In this paper, we propose Adversarial Lightness Attack (ALA), a white-box unrestricted adversarial attack that focuses on modifying the lightness of the images. The shape and color of the samples, which are crucial to human perception, are barely influenced. To obtain adversarial examples with a high attack success rate, we propose unconstrained enhancement in terms of the light and shade relationship in images. To enhance the naturalness of images, we craft the naturalness-aware regularization according to the range and distribution of light. The effectiveness of ALA is verified on two popular datasets for different tasks (i.e., ImageNet for image classification and Places-365 for scene recognition).
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 933209ae-0d3f-4c82-8ce2-3490a7e1a7abCited by top-tier papers6
- Perception-Guided Jailbreak Against Text-to-Image ModelsYihao Huang, Le Liang, Tianlin Li, Xiaojun Jia et al.AAAI 2025 · 34 citations
- Does Few-Shot Learning Suffer from Backdoor Attacks?Xinwei Liu, Xiaojun Jia, Jindong Gu, Yuan Xun et al.AAAI 2024 · 24 citations
- IRAD: Implicit Representation-driven Image Resampling against Adversarial AttacksYue Cao, Tianlin Li, Xiaofeng Cao, Ivor W. Tsang et al.ICLR 2024 · 4 citations
- MAGIC: Mastering Physical Adversarial Generation in Context Through Collaborative LLM AgentsYun Xing, Nhat Chung, Jie Zhang, Yue Cao et al.AAAI 2026
- SceneTAP: Scene-Coherent Typographic Adversarial Planner against Vision-Language Models in Real-World EnvironmentsYue Cao, Yun Xing, Jie Zhang, Di Lin et al.CVPR 2025
Builds on9
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face RecognitionMahmood Sharif, Sruti Bhagavatula, Lujo Bauer, Michael K. ReiterCCS 2016 · 1,765 citations
- LAS-AT: Adversarial Training with Learnable Attack StrategyXiaojun Jia, Yong Zhang, Baoyuan Wu, Ke Ma et al.CVPR 2022 · 140 citations
- Semantic Adversarial Attacks: Parametric Transformations That Fool Deep ClassifiersAmeya Joshi, Amitangshu Mukherjee, Soumik Sarkar, Chinmay HegdeICCV 2019 · 114 citations
- Watch out! Motion is Blurring the Vision of Your Deep Neural NetworksQing Guo, Felix Juefei-Xu, Xiaofei Xie, Lei Ma et al.NeurIPS 2020 · 76 citations
Related papers
- Natural Color Fool: Towards Boosting Black-box Unrestricted AttacksShengming Yuan, Qilong Zhang, Lianli Gao, Yaya Cheng et al.NeurIPS 2022 · 86 citations
- ColorFool: Semantic Adversarial ColorizationAli Shahin Shamsabadi, Ricardo Sánchez-Matilla, Andrea CavallaroCVPR 2020
- Unrestricted Adversarial Examples via Semantic ManipulationAnand Bhattad, Min Jin Chong, Kaizhao Liang, Bo Li et al.ICLR 2020 · 177 citations
- Towards Feature Space Adversarial Attack by Style PerturbationQiuling Xu, Guanhong Tao, Siyuan Cheng, Xiangyu ZhangAAAI 2021 · 33 citations
- DiffAdvMAP: Flexible Diffusion-Based Framework for Generating Natural Unrestricted Adversarial ExamplesZhengzhao Pan, Hua Chen, Xiaogang ZhangICML 2025
