Enhancing Adversarial Attacks: The Similar Target Method

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Zhang, Shuo, Wang, Ziruo, Zhou, Zikai, Chen, Huanran
Formato: Preprint
Publicado: 2023
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866929239905796096
author Zhang, Shuo
Wang, Ziruo
Zhou, Zikai
Chen, Huanran
author_facet Zhang, Shuo
Wang, Ziruo
Zhou, Zikai
Chen, Huanran
contents Deep neural networks are vulnerable to adversarial examples, posing a threat to the models' applications and raising security concerns. An intriguing property of adversarial examples is their strong transferability. Several methods have been proposed to enhance transferability, including ensemble attacks which have demonstrated their efficacy. However, prior approaches simply average logits, probabilities, or losses for model ensembling, lacking a comprehensive analysis of how and why model ensembling significantly improves transferability. In this paper, we propose a similar targeted attack method named Similar Target~(ST). By promoting cosine similarity between the gradients of each model, our method regularizes the optimization direction to simultaneously attack all surrogate models. This strategy has been proven to enhance generalization ability. Experimental results on ImageNet validate the effectiveness of our approach in improving adversarial transferability. Our method outperforms state-of-the-art attackers on 18 discriminative classifiers and adversarially trained models.
format Preprint
id arxiv_https___arxiv_org_abs_2308_10743
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Enhancing Adversarial Attacks: The Similar Target Method
Zhang, Shuo
Wang, Ziruo
Zhou, Zikai
Chen, Huanran
Computer Vision and Pattern Recognition
Cryptography and Security
Deep neural networks are vulnerable to adversarial examples, posing a threat to the models' applications and raising security concerns. An intriguing property of adversarial examples is their strong transferability. Several methods have been proposed to enhance transferability, including ensemble attacks which have demonstrated their efficacy. However, prior approaches simply average logits, probabilities, or losses for model ensembling, lacking a comprehensive analysis of how and why model ensembling significantly improves transferability. In this paper, we propose a similar targeted attack method named Similar Target~(ST). By promoting cosine similarity between the gradients of each model, our method regularizes the optimization direction to simultaneously attack all surrogate models. This strategy has been proven to enhance generalization ability. Experimental results on ImageNet validate the effectiveness of our approach in improving adversarial transferability. Our method outperforms state-of-the-art attackers on 18 discriminative classifiers and adversarially trained models.
title Enhancing Adversarial Attacks: The Similar Target Method
topic Computer Vision and Pattern Recognition
Cryptography and Security
url https://arxiv.org/abs/2308.10743