Dynamic Generative Targeted Attacks with Pattern Injection
Weiwei Feng, Nanqing Xu, Tianzhu Zhang, Yongdong Zhang
Abstract
Adversarial attacks can evaluate model robustness and have been of great concern in recent years. Among various attacks, targeted attacks aim at misleading victim models to output adversary-desired predictions, which are more challenging and threatening than untargeted ones. Existing targeted attacks can be roughly divided into instance-specific and instance-agnostic attacks. Instance-specific attacks craft adversarial examples via iterative gradient updating on the specific instance. In contrast, instance-agnostic attacks learn a universal perturbation or a generative model on the global dataset to perform attacks. However, they rely too much on the classification boundary of substitute models, ignoring the realistic distribution of the target class, which may result in limited targeted attack performance. And there is no attempt to simultaneously combine the information of the specific instance and the global dataset. To deal with these limitations, we first conduct an analysis via a causal graph and propose to craft transferable targeted adversarial examples by injecting target patterns. Based on this analysis, we introduce a generative attack model composed of a cross-attention guided convolution module and a pattern injection module. Concretely, the former adopts a dynamic convolution kernel and a static convolution kernel for the specific instance and the global dataset, respectively, which can inherit the advantages of both instancespecific and instance-agnostic attacks. And the pattern injection module utilizes a pattern prototype to encode target patterns, which can guide the generation of targeted adversarial examples. Besides, we also provide rigorous theoretical analysis to guarantee the effectiveness of our method. Extensive experiments demonstrate that our method shows superior performance than 10 existing adversarial attacks against 13 models.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext debe222e-395b-4a2c-810c-bc514e9262f2Cited by top-tier papers7
- PrivateGaze: Preserving User Privacy in Black-box Mobile Gaze Tracking ServicesLingyu Du, Jinyuan Jia, Xucong Zhang, Guohao LanUbiComp 2024 · 9 citations
- One Perturbation is Enough: On Generating Universal Adversarial Perturbations Against Vision-Language Pre-Training ModelsHao Fang, Jiawei Kong, Wenbo Yu, Bin Chen et al.ICCV 2025 · 8 citations
- Adversarial Attacks Already Tell the Answer: Directional Bias-Guided Test-time Defense for Vision-Language ModelsLiangsheng Liu, Si Chen, Jiamin Wu, Weiwei Feng et al.ICLR 2026 · 4 citations
- Sustainable Self-evolution Adversarial TrainingWenxuan Wang, Chenglei Wang, Huihui Qi, Menghao Ye et al.ACM MM 2024 · 2 citations
- Dual-Flow: Transferable Multi-Target, Instance-Agnostic Attacks via In-the-wild Cascading Flow OptimizationYixiao Chen, Shikun Sun, Jianshu Li, Ruoyu Li et al.NeurIPS 2025 · 1 citation
Builds on10
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- AugMix: A Simple Data Processing Method to Improve Robustness and UncertaintyDan Hendrycks, Norman Mu, Ekin Dogus Cubuk, Barret Zoph et al.ICLR 2020 · 1,572 citations
- Nesterov Accelerated Gradient and Scale Invariance for Adversarial AttacksJiadong Lin, Chuanbiao Song, Kun He, Liwei Wang et al.ICLR 2020 · 765 citations
- Stochastic Variance Reduced Ensemble Adversarial Attack for Boosting the Adversarial TransferabilityYifeng Xiong, Jiadong Lin, Min Zhang, John E. Hopcroft et al.CVPR 2022 · 124 citations
- On Generating Transferable Targeted PerturbationsMuzammal Naseer, Salman H. Khan, Munawar Hayat, Fahad Shahbaz Khan et al.ICCV 2021 · 93 citations
Related papers
- Towards Transferable Targeted Adversarial ExamplesZhibo Wang, Hongshan Yang, Yunhe Feng, Peng Sun et al.CVPR 2023
- AGS: Affordable and Generalizable Substitute Training for Transferable Adversarial AttackRuikui Wang, Yuanfang Guo, Yunhong WangAAAI 2024 · 17 citations
- AIM: Additional Image Guided Generation of Transferable Adversarial AttacksTeng Li, Xingjun Ma, Yu-Gang JiangAAAI 2025 · 7 citations
- Learning Universal Adversarial Perturbation by Adversarial ExampleMaosen Li, Yanhua Yang, Kun Wei, Xu Yang et al.AAAI 2022 · 44 citations
- Minimizing Maximum Model Discrepancy for Transferable Black-box Targeted AttacksAnqi Zhao, Tong Chu, Yahao Liu, Wen Li et al.CVPR 2023
