Towards Transferable Targeted Adversarial Examples
Zhibo Wang, Hongshan Yang, Yunhe Feng, Peng Sun, Hengchang Guo, Zhifei Zhang, Kui Ren
Abstract
Transferability of adversarial examples is critical for black-box deep learning model attacks. While most existing studies focus on enhancing the transferability of untargeted adversarial attacks, few of them studied how to generate transferable targeted adversarial examples that can mislead models into predicting a specific class. Moreover, existing transferable targeted adversarial attacks usually fail to sufficiently characterize the target class distribution, thus suffering from limited transferability. In this paper, we propose the Transferable Targeted Adversarial Attack (TTAA), which can capture the distribution information of the target class from both label-wise and feature-wise perspectives, to generate highly transferable targeted adversarial examples. To this end, we design a generative adversarial training framework consisting of a generator to produce targeted adversarial examples, and feature-label dual discriminators to distinguish the generated adversarial examples from the target class images. Specifically, we design the label discriminator to guide the adversarial examples to learn label-related distribution information about the target class. Meanwhile, we design a feature discriminator, which extracts the feature-wise information with strong cross-model consistency, to enable the adversarial examples to learn the transferable distribution information. Furthermore, we introduce the random perturbation dropping to further enhance the transferability by augmenting the diversity of adversarial examples used in the training process. Experiments demonstrate that our method achieves excellent performance on the transferability of targeted adversarial examples. The targeted fooling rate reaches 95.13% when transferred from VGG-19 to DenseNet-121, which significantly outperforms the state-of-the-art methods.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a0abe9e6-aad1-449e-95da-ae8eb2c118f1Cited by top-tier papers15
- AIM: Additional Image Guided Generation of Transferable Adversarial AttacksTeng Li, Xingjun Ma, Yu-Gang JiangAAAI 2025 · 7 citations
- Enhancing the Adversarial Robustness via Manifold ProjectionZhiting Li, Shibai Yin, Tai-Xiang Jiang, Yexun Hu et al.AAAI 2025 · 5 citations
- Invisible Triggers, Visible Threats! Road-Style Adversarial Creation Attack for Visual 3D Detection in Autonomous DrivingJian Wang, Lijun He, Yixing Yong, Haixia Bi et al.AAAI 2026 · 1 citation
- CT-GAT: Cross-Task Generative Adversarial Attack based on TransferabilityMinxuan Lv, Chengwei Dai, Kun Li, Wei Zhou et al.EMNLP 2023 · 1 citation
- Dual-Flow: Transferable Multi-Target, Instance-Agnostic Attacks via In-the-wild Cascading Flow OptimizationYixiao Chen, Shikun Sun, Jianshu Li, Ruoyu Li et al.NeurIPS 2025 · 1 citation
Builds on10
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Skip Connections Matter: On the Transferability of Adversarial Examples Generated with ResNetsDongxian Wu, Yisen Wang, Shu-Tao Xia, James Bailey et al.ICLR 2020 · 357 citations
- Feature Importance-aware Transferable Adversarial AttacksZhibo Wang, Hengchang Guo, Zhifei Zhang, Wenxin Liu et al.ICCV 2021 · 306 citations
- FDA: Feature Disruptive AttackAditya Ganeshan, Vivek B. S., Venkatesh Babu RadhakrishnanICCV 2019 · 136 citations
- Perturbing Across the Feature Hierarchy to Improve Standard and Strict Blackbox Attack TransferabilityNathan Inkawhich, Kevin J. Liang, Binghui Wang, Matthew Inkawhich et al.NeurIPS 2020 · 105 citations
Related papers
- Transferable Perturbations of Deep Feature DistributionsNathan Inkawhich, Kevin J. Liang, Lawrence Carin, Yiran ChenICLR 2020 · 100 citations
- On Generating Transferable Targeted PerturbationsMuzammal Naseer, Salman H. Khan, Munawar Hayat, Fahad Shahbaz Khan et al.ICCV 2021 · 93 citations
- CDTA: A Cross-Domain Transfer-Based Attack with Contrastive LearningZihan Li, Weibin Wu, Yuxin Su, Zibin Zheng et al.AAAI 2023 · 14 citations
- Focus on Generalization: Improving Adversarial Transferability via Bi-Level Bias MitigationYiqiang Guo, Lei Zhong, Bin Chen, Jia-Li Yin et al.ACM MM 2025
- Dynamic Generative Targeted Attacks with Pattern InjectionWeiwei Feng, Nanqing Xu, Tianzhu Zhang, Yongdong ZhangCVPR 2023
