Structure Invariant Transformation for better Adversarial Transferability
Xiaosen Wang, Zeliang Zhang, Jianping Zhang
Abstract
Given the severe vulnerability of Deep Neural Networks (DNNs) against adversarial examples, there is an urgent need for an effective adversarial attack to identify the deficiencies of DNNs in security-sensitive applications. As one of the prevalent black-box adversarial attacks, the existing transfer-based attacks still cannot achieve comparable performance with the white-box attacks. Among these, input transformation based attacks have shown remarkable effectiveness in boosting transferability. In this work, we find that the existing input transformation based attacks transform the input image globally, resulting in limited diversity of the transformed images. We postulate that the more diverse transformed images result in better transferability. Thus, we investigate how to locally apply various transformations onto the input image to improve such diversity while preserving the structure of image. To this end, we propose a novel input transformation based attack, called Structure Invariant Transformation (SIA), which applies a random image transformation onto each image block to craft a set of diverse images for gradient calculation. Extensive experiments on the standard ImageNet dataset demonstrate that SIA exhibits much better transferability than the existing SOTA input transformation based attacks on CNN-based and transformer-based models, showing its generality and superiority in boosting transferability. Code is available at https://github.com/xiaosen-wang/SIT.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 9c538188-7251-464d-87c4-1759f278b23cCited by top-tier papers36
- Boosting Adversarial Transferability by Achieving Flat Local MaximaZhijin Ge, Xiaosen Wang, Hongying Liu, Fanhua Shang et al.NeurIPS 2023 · 112 citations
- Boosting Adversarial Transferability by Block Shuffle and RotationKunyu Wang, Xuanran He, Wenxuan Wang, Xiaosen WangCVPR 2024 · 61 citations
- Rethinking the Backward Propagation for Adversarial TransferabilityXiaosen Wang, Kangheng Tong, Kun HeNeurIPS 2023 · 45 citations
- Improving the Transferability of Adversarial Examples with Arbitrary Style TransferZhijin Ge, Fanhua Shang, Hongying Liu, Yuanyuan Liu et al.ACM MM 2023 · 31 citations
- Learning to Transform Dynamically for Better Adversarial TransferabilityRongyi Zhu, Zeliang Zhang, Zhuo Liu, Chenliang Xu et al.CVPR 2024 · 18 citations
Builds on23
- Swin Transformer: Hierarchical Vision Transformer using Shifted WindowsZe Liu, Yutong Lin, Yue Cao, Han Hu et al.ICCV 2021 · 31,683 citations
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn et al.ICLR 2021 · 21,477 citations
- CutMix: Regularization Strategy to Train Strong Classifiers With Localizable FeaturesSangdoo Yun, Dongyoon Han, Sanghyuk Chun, Seong Joon Oh et al.ICCV 2019 · 5,843 citations
- Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face RecognitionMahmood Sharif, Sruti Bhagavatula, Lujo Bauer, Michael K. ReiterCCS 2016 · 1,765 citations
- Feature Squeezing: Detecting Adversarial Examples in Deep Neural NetworksWeilin Xu, David Evans, Yanjun QiNDSS 2018 · 1,633 citations
Related papers
- Leveraging Spatial Invariance to Boost Adversarial TransferabilityZihan Zhou, Li Li, Yanli Ren, Chuan Qin et al.ICCV 2025 · 1 citation
- Improving the Transferability of Adversarial Samples With Adversarial TransformationsWeibin Wu, Yuxin Su, Michael R. Lyu, Irwin KingCVPR 2021
- Admix: Enhancing the Transferability of Adversarial AttacksXiaosen Wang, Xuanran He, Jingdong Wang, Kun HeICCV 2021 · 282 citations
- Blurred-Dilated Method for Adversarial AttacksYang Deng, Weibin Wu, Jianping Zhang, Zibin ZhengNeurIPS 2023 · 10 citations
- Improving the Transferability of Targeted Adversarial Examples through Object-Based Diverse InputJunyoung Byun, Seungju Cho, Myung-Joon Kwon, Hee-Seon Kim et al.CVPR 2022 · 67 citations
