I-C Attack: In-place and Cross-pixel Augmentations for Highly Transferable Transformation-based Attacks
Jiaming Liang, Chi-Man Pun
摘要
The efficiency and high transferability of transformation-based adversarial attacks (TAAs) make them a promising tool for robustness analysis. Despite the improvements in transferability brought by various image transformations, their underlying causes remain unclear, and there is still room for further improvement. We find that with attention-based models as surrogate models, adversarial examples generated by TAAs with relatively lower transferability tend to exhibit checkerboard artifacts, whereas those with higher transferability do not. This motivates us to explore the relationship between transferability and checkerboard artifacts. We confirm that checkerboard artifacts originate from the patching operation in attention-based surrogate models. Checkerboard artifacts vanish under the condition that spatial transformations are applied and gradients are calculated with respect to perturbations. Based on whether checkerboard artifacts are eliminated, we categorize model augmentations into cross-pixel augmentations and in-place augmentations. The former promotes interactions between pixels, breaks patch isolation, and thereby improves transferability while removing artifacts. The latter in-place augment the diversity of parameter features, enhancing transferability but failing to break isolation and remove artifacts. They constitute two distinct ways toward enhancing transferability. Integrating them enables higher transferability. Therefore, we propose an attack design paradigm to fully leverage both augmentations. To verify this paradigm, we design a basic In-place and Cross-pixel Attack (I-C Attack) with simple transformations. Extensive experiments demonstrate that, despite its simplicity, I-C attack can achieve much higher transferability while maintaining low computational cost. The code is available at https://github.com/chinaliangjiaming/I-C-Attack.git.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper2
- OTI: A Model-free and Visually Interpretable Measure of Image AttackabilityJiaming Liang, Haowei Liu, Chi-Man PunAAAI 2026 · 被引用 1 次
- MADA-Attack: Transferable Multi-modal Attention Distraction Adversarial Attack against Vision Language ModelsZhihan Qin, Jiahao Chen, Chunyi Zhou, Yuwen Pu 等ICML 2026
相关 Paper
- Transferability Bound Theory: Exploring Relationship between Adversarial Transferability and FlatnessMingyuan Fan, Xiaodan Li, Cen Chen, Wenmeng Zhou 等NeurIPS 2024 · 被引用 13 次
- Everywhere Attack: Attacking Locally and Globally to Boost Targeted TransferabilityHui Zeng, Sanshuai Cui, Biwei Chen, Anjie PengAAAI 2025 · 被引用 4 次
- Boosting Adversarial Transferability by Block Shuffle and RotationKunyu Wang, Xuanran He, Wenxuan Wang, Xiaosen WangCVPR 2024 · 被引用 61 次
- Admix: Enhancing the Transferability of Adversarial AttacksXiaosen Wang, Xuanran He, Jingdong Wang, Kun HeICCV 2021 · 被引用 282 次
- Generating Transferable Adversarial Examples against Vision TransformersYuxuan Wang, Jiakai Wang, Zixin Yin, Ruihao Gong 等ACM MM 2022 · 被引用 25 次
