CDTA: A Cross-Domain Transfer-Based Attack with Contrastive Learning
Zihan Li, Weibin Wu, Yuxin Su, Zibin Zheng, Michael R. Lyu
摘要
Despite the excellent performance, deep neural networks (DNNs) have been shown to be vulnerable to adversarial examples. Besides, these examples are often transferable among different models. In other words, the same adversarial example can fool multiple models with different architectures at the same time. Based on this property, many black-box transfer-based attack techniques have been developed. However, current transfer-based attacks generally focus on the cross-architecture setting, where the attacker has access to the training data of the target model, which is not guaranteed in realistic situations. In this paper, we design a Cross-Domain Transfer-Based Attack (CDTA), which works in the cross-domain scenario. In this setting, attackers have no information about the target model, such as its architecture and training data. Specifically, we propose a contrastive spectral training method to train a feature extractor on a source domain (e.g., ImageNet) and use it to craft adversarial examples on target domains (e.g., Oxford 102 Flower). Our method corrupts the semantic information of the benign image by scrambling the outputs of both the intermediate feature layers and the final layer of the feature extractor. We evaluate CDTA with 16 target deep models on four datasets with widely varying styles. The results confirm that, in terms of the attack success rate, our approach can consistently outperform the state-of-the-art baselines by an average of 11.45% across all target models. Our code is available at https://github.com/LiulietLee/CDTA.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- AGS: Affordable and Generalizable Substitute Training for Transferable Adversarial AttackRuikui Wang, Yuanfang Guo, Yunhong WangAAAI 2024 · 被引用 17 次
- AIM: Additional Image Guided Generation of Transferable Adversarial AttacksTeng Li, Xingjun Ma, Yu-Gang JiangAAAI 2025 · 被引用 7 次
- Prompt-Driven Transferable Adversarial Attack on Person Re-identification with Attribute-Aware Textual InversionYuan Bian, Min Liu, Yunqi Yi, Xueping Wang 等ICCV 2025 · 被引用 3 次
- PGA: Prior-free Generative Attack for Practical No-box Scenariohongyu peng, Xiang Yuan, Gong ChengCVPR 2026
它引用的顶会 Paper15
- Bootstrap Your Own Latent - A New Approach to Self-Supervised LearningJean-Bastien Grill, Florian Strub, Florent Altché, Corentin Tallec 等NeurIPS 2020 · 被引用 9,171 次
- What Makes for Good Views for Contrastive Learning?Yonglong Tian, Chen Sun, Ben Poole, Dilip Krishnan 等NeurIPS 2020 · 被引用 1,631 次
- Feature Importance-aware Transferable Adversarial AttacksZhibo Wang, Hengchang Guo, Zhifei Zhang, Wenxin Liu 等ICCV 2021 · 被引用 306 次
- FDA: Feature Disruptive AttackAditya Ganeshan, Vivek B. S., Venkatesh Babu RadhakrishnanICCV 2019 · 被引用 136 次
- Towards Cross-Modality Medical Image Segmentation with Online Mutual Knowledge DistillationKang Li, Lequan Yu, Shujun Wang, Pheng-Ann HengAAAI 2020 · 被引用 115 次
相关 Paper
- FACL-Attack: Frequency-Aware Contrastive Learning for Transferable Adversarial AttacksHunmin Yang, Jongoh Jeong, Kuk-Jin YoonAAAI 2024 · 被引用 12 次
- Blurred-Dilated Method for Adversarial AttacksYang Deng, Weibin Wu, Jianping Zhang, Zibin ZhengNeurIPS 2023 · 被引用 10 次
- Beyond ImageNet Attack: Towards Crafting Adversarial Examples for Black-box DomainsQilong Zhang, Xiaodan Li, Yuefeng Chen, Jingkuan Song 等ICLR 2022 · 被引用 85 次
- Towards Transferable Targeted Adversarial ExamplesZhibo Wang, Hongshan Yang, Yunhe Feng, Peng Sun 等CVPR 2023
- Perturbing Across the Feature Hierarchy to Improve Standard and Strict Blackbox Attack TransferabilityNathan Inkawhich, Kevin J. Liang, Binghui Wang, Matthew Inkawhich 等NeurIPS 2020 · 被引用 105 次
