arXiv:2503.00932cs.CVcs.AI2025-03被引 1

仅旋转1度输入即可显著提升对抗样本跨模型攻击效果。

Improving the Transferability of Adversarial Attacks by an Input Transpose

  • 通过输入图像微小旋转(如1度)增强对抗样本的迁移能力。
  • 在不添加任何扰动情况下,旋转即可让攻击成功欺骗多个未见模型。
  • 适用于资源受限场景,无需复杂算法或额外计算开销。

深度神经网络极易受到对抗样本攻击——对输入施加人类难以察觉的微小扰动,却会导致错误预测。但在黑盒场景中,现有对抗样本的迁移能力有限,难以有效攻破多个未知模型。以往方法通过提升扰动的多样性来增强跨模型泛化能力,但常需复杂算法和大量计算。本文提出一种输入转置方法,几乎不增加额外成本,却能显著提升现有对抗策略的迁移性。即使不添加任何对抗扰动,仅对输入进行1°左右的旋转,便能使多数对抗样本成功欺骗未见过的模型。分析表明,这种迁移性提升可能源于神经网络低层特征图中可见模式的微小偏移。此外,在无限制查询条件下识别最优旋转角度,或可进一步提升攻击性能。

原文摘要 · Abstract (English)

Deep neural networks (DNNs) are highly susceptible to adversarial examples--subtle perturbations applied to inputs that are often imperceptible to humans yet lead to incorrect model predictions. In black-box scenarios, however, existing adversarial examples exhibit limited transferability and struggle to effectively compromise multiple unseen DNN models. Previous strategies enhance the cross-model generalization of adversarial examples by introducing versatility into adversarial perturbations, thereby improving transferability. However, further refining perturbation versatility often demands intricate algorithm development and substantial computation consumption. In this work, we propose an input transpose method that requires almost no additional labor and computation costs but can significantly improve the transferability of existing adversarial strategies. Even without adding adversarial perturbations, our method demonstrates considerable effectiveness in cross-model attacks. Our exploration finds that on specific datasets, a mere $1^\circ$ left or right rotation might be sufficient for most adversarial examples to deceive unseen models. Our further analysis suggests that this transferability improvement triggered by rotating only $1^\circ$ may stem from visible pattern shifts in the DNN's low-level feature maps. Moreover, this transferability exhibits optimal angles that, when identified under unrestricted query conditions, could potentially yield even greater performance.

对抗攻击迁移性输入变换

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。