Rethinking Adversarial Transferability from a Data Distribution Perspective
Yao Zhu, Jiacheng Sun, Zhenguo Li
摘要
Adversarial transferability enables attackers to generate adversarial examples from the source model to attack the target model, which has raised security concerns about the deployment of DNNs in practice. In this paper, we rethink adversarial transferability from a data distribution perspective and further enhance transferability by score matching based optimization. We identify that some samples with injecting small Gaussian noise can fool different target models, and their adversarial examples under different source models have much stronger transferability. We hypothesize that these samples are in the low-density region of the ground truth distribution where models are not well trained. To improve the attack success rate of adversarial examples, we match the adversarial attacks with the directions which effectively decrease the ground truth density. We propose Intrinsic Adversarial Attack (IAA), which smooths the activation function and decreases the impact of the later layers of a given normal model, to increase the alignment of adversarial attack and the gradient of joint data distribution. We conduct comprehensive transferable attacks against multiple DNNs and show that our IAA can boost the transferability of the crafted attacks in all cases and go beyond state-of-the-art methods.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper9
- Boosting Out-of-distribution Detection with Typical FeaturesYao Zhu, Yuefeng Chen, Chuanlong Xie, Xiaodan Li 等NeurIPS 2022 · 被引用 74 次
- Elucidating the design space of classifier-guided diffusion generationJiajun Ma, Tianyang Hu, Wenjia Wang, Jiacheng SunICLR 2024 · 被引用 24 次
- Molecule Joint Auto-Encoding: Trajectory Pretraining with 2D and 3D DiffusionWeitao Du, Jiujiu Chen, Xuecang Zhang, Zhi-Ming Ma 等NeurIPS 2023 · 被引用 15 次
- Perturbation Towards Easy Samples Improves Targeted Adversarial TransferabilityJunqi Gao, Biqing Qi, Yao Li, Zhichang Guo 等NeurIPS 2023 · 被引用 11 次
- Harnessing the Computation Redundancy in ViTs to Boost Adversarial TransferabilityJiani Liu, Zhiyuan Wang, Zeliang Zhang, Chao Huang 等NeurIPS 2025 · 被引用 7 次
相关 Paper
- StyLess: Boosting the Transferability of Adversarial ExamplesKaisheng Liang, Bin XiaoCVPR 2023
- Making Substitute Models More Bayesian Can Enhance Transferability of Adversarial ExamplesQizhang Li, Yiwen Guo, Wangmeng Zuo, Hao ChenICLR 2023 · 被引用 5 次
- Towards Transferable Targeted Adversarial ExamplesZhibo Wang, Hongshan Yang, Yunhe Feng, Peng Sun 等CVPR 2023
- Learning Transferable Adversarial PerturbationsKrishna Kanth Nakka, Mathieu SalzmannNeurIPS 2021 · 被引用 75 次
- Improving the Transferability of Adversarial Samples With Adversarial TransformationsWeibin Wu, Yuxin Su, Michael R. Lyu, Irwin KingCVPR 2021
