Everywhere Attack: Attacking Locally and Globally to Boost Targeted Transferability
Hui Zeng, Sanshuai Cui, Biwei Chen, Anjie Peng
Abstract
Adversarial examples’ (AE) transferability refers to the phenomenon that AEs crafted with one surrogate model can also fool other models. Notwithstanding remarkable progress in untargeted transferability, its targeted counterpart remains challenging. This paper proposes an everywhere scheme to boost targeted transferability. Our idea is to attack a victim image both globally and locally. We aim to optimize ‘an army of targets’ in every local image region instead of the previous works that optimize a high-confidence target in the image. Specifically, we split a victim image into non-overlap blocks and jointly mount a targeted attack on each block. Such a strategy mitigates transfer failures caused by attention inconsistency between surrogate and victim models and thus results in stronger transferability. Our approach is method-agnostic, which means it can be easily combined with existing transferable attacks for even higher transferability. Extensive experiments on ImageNet demonstrate that the proposed approach universally improves the state-of-the-art targeted attacks by a clear margin, e.g., the transferability of the widely adopted Logit attack can be improved by 28.8%-300%. We also evaluate the crafted AEs on a real-world platform: Google Cloud Vision. Results further support the superiority of the proposed method.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext da483614-b8a3-4a21-ae2a-4da7fcacd722Cited by top-tier papers1
Ask how each one uses itBuilds on11
- Swin Transformer: Hierarchical Vision Transformer using Shifted WindowsZe Liu, Yutong Lin, Yue Cao, Han Hu et al.ICCV 2021 · 31,683 citations
- Admix: Enhancing the Transferability of Adversarial AttacksXiaosen Wang, Xuanran He, Jingdong Wang, Kun HeICCV 2021 · 282 citations
- On Success and Simplicity: A Second Look at Transferable Targeted AttacksZhengyu Zhao, Zhuoran Liu, Martha A. LarsonNeurIPS 2021 · 173 citations
- Learning Transferable Adversarial Examples via Ghost NetworksYingwei Li, Song Bai, Yuyin Zhou, Cihang Xie et al.AAAI 2020 · 158 citations
- Transferable Perturbations of Deep Feature DistributionsNathan Inkawhich, Kevin J. Liang, Lawrence Carin, Yiran ChenICLR 2020 · 100 citations
Related papers
- Learning to Learn Transferable AttackShuman Fang, Jie Li, Xianming Lin, Rongrong JiAAAI 2022 · 26 citations
- Boosting the Transferability of Adversarial Attacks with Reverse Adversarial PerturbationZeyu Qin, Yanbo Fan, Yi Liu, Li Shen et al.NeurIPS 2022 · 135 citations
- I-C Attack: In-place and Cross-pixel Augmentations for Highly Transferable Transformation-based AttacksJiaming Liang, Chi-Man PunACM MM 2025 · 3 citations
- Boosting Adversarial Transferability with Spatial Adversarial AlignmentZhaoyu Chen, Haijing Guo, Kaixun Jiang, Jiyuan Fu et al.NeurIPS 2025 · 4 citations
- Boosting the Transferability of Adversarial Samples via AttentionWeibin Wu, Yuxin Su, Xixian Chen, Shenglin Zhao et al.CVPR 2020
