arXiv:2411.15553cs.CV2024-11CVPR被引 14

通过特征空间优化噪声提升攻击迁移性,低成本实现精准误导。

Improving Transferable Targeted Attacks with Feature Tuning Mixup

  • 在特征空间引入可学习扰动,结合随机与优化噪声
  • 在ImageNet类数据集上显著提升目标攻击迁移率
  • 适合研究对抗攻击迁移机制或防御评估的开发者

深度神经网络对可迁移的对抗样本存在漏洞。针对特定目标类别进行误导的转移性攻击尤为困难。现有方法虽提升攻击迁移性,但计算开销大且增益有限。近期的干净特征混合方法使用随机清洁特征扰动特征空间,却未针对对抗样本进行优化,忽视了攻击特异性扰动的优势。本文提出特征调优混合(FTM),通过在特征空间中结合随机与优化噪声,增强目标攻击的迁移能力。FTM引入可学习的特征扰动,并采用高效的随机更新策略进行优化,生成更具鲁棒性的对抗样本,提升迁移性能。进一步证明,通过多个FTM扰动的代理模型集成可增强攻击效果。在多种DNN模型上的ImageNet兼容数据集实验表明,该方法在保持低计算成本的前提下,显著优于当前最优方法。

原文摘要 · Abstract (English)

Deep neural networks (DNNs) exhibit vulnerability to adversarial examples that can transfer across different DNN models. A particularly challenging problem is developing transferable targeted attacks that can mislead DNN models into predicting specific target classes. While various methods have been proposed to enhance attack transferability, they often incur substantial computational costs while yielding limited improvements. Recent clean feature mixup methods use random clean features to perturb the feature space but lack optimization for disrupting adversarial examples, overlooking the advantages of attack-specific perturbations. In this paper, we propose Feature Tuning Mixup (FTM), a novel method that enhances targeted attack transferability by combining both random and optimized noises in the feature space. FTM introduces learnable feature perturbations and employs an efficient stochastic update strategy for optimization. These learnable perturbations facilitate the generation of more robust adversarial examples with improved transferability. We further demonstrate that attack performance can be enhanced through an ensemble of multiple FTM-perturbed surrogate models. Extensive experiments on the ImageNet-compatible dataset across various DNN models demonstrate that our method achieves significant improvements over state-of-the-art methods while maintaining low computational cost.

对抗攻击特征扰动迁移性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。