通过梯度引导的数据变换,提升对抗样本的迁移能力。
GADT: Enhancing Transferable Adversarial Attacks through Gradient-guided Adversarial Data Transformation
- 用可微分数据增强库搜索最优变换参数,结合对抗噪声迭代优化。
- 在多个模型上实现更高迁移率,攻击成功率提升显著。
- 适合研究真实场景下黑箱攻击,尤其适用于查询受限环境。
当前可迁移对抗样本主要通过添加对抗噪声生成。近期研究强调需联合优化数据增强(DA)参数与对抗噪声,以对现实世界AI系统构成更大威胁。然而,现有基于DA的策略常因缺乏有效指导而难以找到最优解。本文提出新型基于数据增强的攻击方法GADT:通过迭代对抗性搜索确定合适的DA参数,并利用后验估计更新对抗噪声。我们首次引入可微分的DA操作库识别对抗性增强参数,设计新损失函数作为优化指标,在增强攻击效果的同时保留原始图像内容,维持攻击隐蔽性。大量实验表明,GADT可无缝集成至现有可迁移攻击方法中,有效更新其数据增强参数并保持原有噪声生成策略;同时适用于其他黑盒攻击场景(如查询型攻击),为研究与工业界提升真实应用中的攻击效能提供新路径。
原文摘要 · Abstract (English)
Current Transferable Adversarial Examples (TAE) are primarily generated by adding Adversarial Noise (AN). Recent studies emphasize the importance of optimizing Data Augmentation (DA) parameters along with AN, which poses a greater threat to real-world AI applications. However, existing DA-based strategies often struggle to find optimal solutions due to the challenging DA search procedure without proper guidance. In this work, we propose a novel DA-based attack algorithm, GADT. GADT identifies suitable DA parameters through iterative antagonism and uses posterior estimates to update AN based on these parameters. We uniquely employ a differentiable DA operation library to identify adversarial DA parameters and introduce a new loss function as a metric during DA optimization. This loss term enhances adversarial effects while preserving the original image content, maintaining attack crypticity. Extensive experiments on public datasets with various networks demonstrate that GADT can be integrated with existing transferable attack methods, updating their DA parameters effectively while retaining their AN formulation strategies. Furthermore, GADT can be utilized in other black-box attack scenarios, e.g., query-based attacks, offering a new avenue to enhance attacks on real-world AI applications in both research and industrial contexts.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。