arXiv:2605.18919cs.CRcs.AI2026-05

用连续路径优化提升无梯度攻击效率,让对抗样本更易迁移。

MoCo-EA: Exploiting Adversarial Mode Connectivity for Efficient Evolutionary Attacks

论文配图:MoCo-EA: Exploiting Adversarial Mode Connectivity for Efficient Evolutionary Attacks
图 1 · 摘自论文原文
  • 用贝塞尔曲线替代传统交叉操作,实现扰动的连续演化
  • 中间点攻击成功率高于起点终点,且迁移能力更强
  • 查询次数减少一半,收敛速度更快,适合高效攻击场景

无梯度对抗攻击中的进化算法依赖种群搜索发现扰动,但传统交叉操作因离散插值会破坏对抗性。本文提出模式连通性进化攻击(MoCo-EA),以新型贝塞尔交叉算子替代传统方法,沿父代扰动间的连续贝塞尔曲线优化扰动。关键发现包括:(1) 成功的对抗扰动具有模式连通性;(2) 优化路径上的中间点比端点具备更高迁移性;(3) 贝塞尔交叉显著优于离散遗传操作,大幅降低收敛时间和查询次数。通过路径优化挖掘对抗空间的几何结构,MoCo-EA提供了一种高效可靠的攻击方法。本工作挑战了对抗样本为孤立点的传统观点,为攻击与防御研究开辟新方向。

原文摘要 · Abstract (English)

Evolutionary algorithms for adversarial attacks leverage population-based search to discover perturbations without gradient information, but suffer from inefficient crossover operations that destroy adversarial properties through discrete interpolation. We introduce Mode Connectivity Evolutionary Attack (MoCo-EA), which replaces traditional crossover with a novel Bézier crossover operator that optimizes perturbations along a continuous Bézier curve between parent perturbations. Our key insight is that adversarial examples lie on connected manifolds where intermediate points maintain and often enhance attack effectiveness. We demonstrate three findings: (1) Successful adversarial perturbations exhibit mode connectivity; (2) Intermediate points along optimized paths achieve higher transferability than endpoints; (3) Bézier crossover dramatically outperforms discrete genetic operations while reducing convergence time and query requirements. By exploiting the geometric structure of adversarial space through path optimization, MoCo-EA provides an efficient and reliable method. Our work challenges the traditional view of adversarial examples as isolated points and opens new directions for both attack generation and defense research.

对抗攻击进化算法路径优化迁移性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。