arXiv:2512.14188cs.LG2025-12被引 1

提出新型自适应动量攻击,提升对抗样本迁移性与稳定性

Optimizing the Adversarial Perturbation with a Momentum-based Adaptive Matrix

  • 用动量自适应矩阵替代传统符号函数,优化扰动方向
  • 在多种网络上实现更强迁移性,攻击成功率超现有方法
  • 理论证明收敛性,适合研究对抗攻击与防御的学者

生成对抗样本可视为优化问题。现有基于梯度的攻击如PGD和MI-FGSM广泛使用符号函数缩放扰动,引发优化理论上的质疑。本文揭示PGD实为仅用当前梯度确定步长的投影梯度法特例,并证明使用累积梯度的自适应矩阵时PGD等价于AdaGrad。受此启发,提出新型动量自适应攻击AdaMI,其扰动通过动量自适应矩阵优化。理论证明该方法对凸问题具有最优收敛性,解决了MI-FGSM的非收敛问题,保障优化过程稳定。实验表明,该方法在不同网络间显著提升对抗样本迁移性,优于现有最优方法,同时保持更好稳定性和不可察觉性。

原文摘要 · Abstract (English)

Generating adversarial examples (AEs) can be formulated as an optimization problem. Among various optimization-based attacks, the gradient-based PGD and the momentum-based MI-FGSM have garnered considerable interest. However, all these attacks use the sign function to scale their perturbations, which raises several theoretical concerns from the point of view of optimization. In this paper, we first reveal that PGD is actually a specific reformulation of the projected gradient method using only the current gradient to determine its step-size. Further, we show that when we utilize a conventional adaptive matrix with the accumulated gradients to scale the perturbation, PGD becomes AdaGrad. Motivated by this analysis, we present a novel momentum-based attack AdaMI, in which the perturbation is optimized with an interesting momentum-based adaptive matrix. AdaMI is proved to attain optimal convergence for convex problems, indicating that it addresses the non-convergence issue of MI-FGSM, thereby ensuring stability of the optimization process. The experiments demonstrate that the proposed momentum-based adaptive matrix can serve as a general and effective technique to boost adversarial transferability over the state-of-the-art methods across different networks while maintaining better stability and imperceptibility.

对抗攻击优化方法自适应矩阵

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。