arXiv:2410.13891cs.CRcs.AI2024-10TPAMI被引 1

提出无需数据的快速攻击方法,仅靠缩放提升攻击迁移性。

S$^4$ST: A Strong, Self-transferable, faSt, and Simple Scale Transformation for Transferable Targeted Attack

  • 用自对齐与自迁移性评估变换效果,无需黑盒反馈。
  • 缩放变换显著提升目标迁移攻击性能,优于复杂方法。
  • 适合研究模型安全与对抗攻击的学者快速复现使用。

迁移式定向攻击(TTA)因严重过拟合于代理模型而面临挑战。近期进展依赖大量受害者模型训练数据,而无数据方案(如图像变换梯度优化)通常需黑盒反馈进行设计与调参,违背黑盒设置并影响威胁评估公平性。本文提出两种盲估计指标——自对齐与自迁移性,在严格黑盒约束下分析每种变换的有效性及跨变换相关性。发现:(1)仅缩放变换能显著增强定向迁移性,优于其他基础变换并媲美领先复杂方法;(2)几何与色彩变换内部冗余高,但类别间相关性弱。基于此设计S⁴ST(强、自迁移、快、简缩放变换),整合维度一致的缩放、互补低冗余变换与分块操作。跨多种架构、训练分布与任务的实验证明,S⁴ST在无数据依赖下实现最优效能平衡。揭示缩放有效性源于视觉数据的多尺度特性及训练中普遍的缩放增强,使其成双刃剑。医学影像与人脸验证的进一步验证表明框架具备强泛化能力。

原文摘要 · Abstract (English)

Transferable Targeted Attacks (TTAs) face significant challenges due to severe overfitting to surrogate models. Recent breakthroughs heavily rely on large-scale training data of victim models, while data-free solutions, \textit{i.e.}, image transformation-involved gradient optimization, often depend on black-box feedback for method design and tuning. These dependencies violate black-box transfer settings and compromise threat evaluation fairness. In this paper, we propose two blind estimation measures, self-alignment and self-transferability, to analyze per-transformation effectiveness and cross-transformation correlations under strict black-box constraints. Our findings challenge conventional assumptions: (1) Attacking simple scaling transformations uniquely enhances targeted transferability, outperforming other basic transformations and rivaling leading complex methods; (2) Geometric and color transformations exhibit high internal redundancy despite weak inter-category correlations. These insights drive the design and tuning of S$^4$ST (Strong, Self-transferable, faSt, Simple Scale Transformation), which integrates dimensionally consistent scaling, complementary low-redundancy transformations, and block-wise operations. Extensive evaluations across diverse architectures, training distributions, and tasks show that S$^{4}$ST achieves state-of-the-art effectiveness-efficiency balance without data dependency. We reveal that scaling's effectiveness stems from visual data's multi-scale nature and ubiquitous scale augmentation during training, rendering such augmentation a double-edged sword. Further validations on medical imaging and face verification confirm the framework's strong generalization.

对抗攻击迁移攻击无数据

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。