GreedyFool: Distortion-Aware Sparse Adversarial Attack
Xiaoyi Dong, Dongdong Chen, Jianmin Bao, Chuan Qin, Lu Yuan, Weiming Zhang, Nenghai Yu, Dong Chen
Abstract
Modern deep neural networks(DNNs) are vulnerable to adversarial samples. Sparse adversarial samples are a special branch of adversarial samples that can fool the target model by only perturbing a few pixels. The existence of the sparse adversarial attack points out that DNNs are much more vulnerable than people believed, which is also a new aspect for analyzing DNNs. However, current sparse adversarial attack methods still have some shortcomings on both sparsity and invisibility. In this paper, we propose a novel two-stage distortion-aware greedy-based method dubbed as "GreedyFool". Specifically, it first selects the most effective candidate positions to modify by considering both the gradient(for adversary) and the distortion map(for invisibility), then drops some less important points in the reduce stage. Experiments demonstrate that compared with the startof-the-art method, we only need to modify 3× fewer pixels under the same sparse perturbation setting. For target attack, the success rate of our method is 9.96% higher than the start-of-the-art method under the same pixel budget. Code can be found at https://github.com/LightDXY/GreedyFool .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a1ab4bb3-13c9-419c-9387-8bcadb23bf2dCited by top-tier papers9
- Patch-Fool: Are Vision Transformers Always Robust Against Adversarial Perturbations?Yonggan Fu, Shunyao Zhang, Shang Wu, Cheng Wan et al.ICLR 2022 · 86 citations
- Sparse and Imperceptible Adversarial Attack via a Homotopy AlgorithmMingkang Zhu, Tianlong Chen, Zhangyang WangICML 2021 · 33 citations
- Improving Adversarial Robustness of Masked Autoencoders via Test-time Frequency-domain PromptingQidong Huang, Xiaoyi Dong, Dongdong Chen, Yinpeng Chen et al.ICCV 2023 · 15 citations
- Transferable Structural Sparse Adversarial Attack Via Exact Group Sparsity TrainingDi Ming, Peng Ren, Yunlong Wang, Xin FengCVPR 2024 · 7 citations
- One-Pixel Shortcut: On the Learning Preference of Deep Neural NetworksShutong Wu, Sizhe Chen, Cihang Xie, Xiaolin HuangICLR 2023 · 4 citations
Builds on8
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Feature Squeezing: Detecting Adversarial Examples in Deep Neural NetworksWeilin Xu, David Evans, Yanjun QiNDSS 2018 · 1,633 citations
- MagNet: A Two-Pronged Defense against Adversarial ExamplesDongyu Meng, Hao ChenCCS 2017 · 1,295 citations
- Sparse and Imperceivable Adversarial AttacksFrancesco Croce, Matthias HeinICCV 2019 · 228 citations
- Once a MAN: Towards Multi-Target Attack via Learning Multi-Target Adversarial Network OnceJiangfan Han, Xiaoyi Dong, Ruimao Zhang, Dongdong Chen et al.ICCV 2019 · 31 citations
Related papers
- Black-Box Sparse Adversarial Attack via Multi-Objective Optimisation CVPR ProceedingsPhoenix Neale Williams, Ke LiCVPR 2023
- A Geometry-Inspired Decision-Based AttackYujia Liu, Seyed-Mohsen Moosavi-Dezfooli, Pascal FrossardICCV 2019 · 55 citations
- Robust Superpixel-Guided Attentional Adversarial AttackXiaoyi Dong, Jiangfan Han, Dongdong Chen, Jiayang Liu et al.CVPR 2020
- GSE: Group-wise Sparse and Explainable Adversarial AttacksShpresim Sadiku, Moritz Wagner, Sebastian PokuttaICLR 2025
- FeatureFool: Zero-Query Fooling of Video Models via Feature MapDuoxun Tang, Xi Xiao, Guangwu Hu, Kangkang Sun et al.CVPR 2026 · 1 citation
