Improving Transferability of Adversarial Examples via Bayesian Attacks

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Li, Qizhang, Guo, Yiwen, Yang, Xiaochen, Zuo, Wangmeng, Chen, Hao
Format: Preprint
Published: 2023
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866918160608788480
author Li, Qizhang
Guo, Yiwen
Yang, Xiaochen
Zuo, Wangmeng
Chen, Hao
author_facet Li, Qizhang
Guo, Yiwen
Yang, Xiaochen
Zuo, Wangmeng
Chen, Hao
contents The transferability of adversarial examples allows for the attack on unknown deep neural networks (DNNs), posing a serious threat to many applications and attracting great attention. In this paper, we improve the transferability of adversarial examples by incorporating the Bayesian formulation into both the model parameters and model input, enabling their joint diversification. We demonstrate that combination of Bayesian formulations for both the model input and model parameters yields significant improvements in transferability. By introducing advanced approximations of the posterior distribution over the model input, adversarial transferability achieves further enhancement, surpassing all state-of-the-arts when attacking without model fine-tuning. Additionally, we propose a principled approach to fine-tune model parameters within this Bayesian framework. Extensive experiments demonstrate that our method achieves a new state-of-the-art in transfer-based attacks, significantly improving the average success rate on ImageNet and CIFAR-10. Code at: https://github.com/qizhangli/MoreBayesian-jrnl.
format Preprint
id arxiv_https___arxiv_org_abs_2307_11334
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Improving Transferability of Adversarial Examples via Bayesian Attacks
Li, Qizhang
Guo, Yiwen
Yang, Xiaochen
Zuo, Wangmeng
Chen, Hao
Machine Learning
Cryptography and Security
Computer Vision and Pattern Recognition
The transferability of adversarial examples allows for the attack on unknown deep neural networks (DNNs), posing a serious threat to many applications and attracting great attention. In this paper, we improve the transferability of adversarial examples by incorporating the Bayesian formulation into both the model parameters and model input, enabling their joint diversification. We demonstrate that combination of Bayesian formulations for both the model input and model parameters yields significant improvements in transferability. By introducing advanced approximations of the posterior distribution over the model input, adversarial transferability achieves further enhancement, surpassing all state-of-the-arts when attacking without model fine-tuning. Additionally, we propose a principled approach to fine-tune model parameters within this Bayesian framework. Extensive experiments demonstrate that our method achieves a new state-of-the-art in transfer-based attacks, significantly improving the average success rate on ImageNet and CIFAR-10. Code at: https://github.com/qizhangli/MoreBayesian-jrnl.
title Improving Transferability of Adversarial Examples via Bayesian Attacks
topic Machine Learning
Cryptography and Security
Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2307.11334