Enhancing Adversarial Transferability via Information Bottleneck Constraints

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Qi, Biqing, Gao, Junqi, Liu, Jianxing, Wu, Ligang, Zhou, Bowen
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909219771383808
author Qi, Biqing
Gao, Junqi
Liu, Jianxing
Wu, Ligang
Zhou, Bowen
author_facet Qi, Biqing
Gao, Junqi
Liu, Jianxing
Wu, Ligang
Zhou, Bowen
contents From the perspective of information bottleneck (IB) theory, we propose a novel framework for performing black-box transferable adversarial attacks named IBTA, which leverages advancements in invariant features. Intuitively, diminishing the reliance of adversarial perturbations on the original data, under equivalent attack performance constraints, encourages a greater reliance on invariant features that contributes most to classification, thereby enhancing the transferability of adversarial attacks. Building on this motivation, we redefine the optimization of transferable attacks using a novel theoretical framework that centers around IB. Specifically, to overcome the challenge of unoptimizable mutual information, we propose a simple and efficient mutual information lower bound (MILB) for approximating computation. Moreover, to quantitatively evaluate mutual information, we utilize the Mutual Information Neural Estimator (MINE) to perform a thorough analysis. Our experiments on the ImageNet dataset well demonstrate the efficiency and scalability of IBTA and derived MILB. Our code is available at https://github.com/Biqing-Qi/Enhancing-Adversarial-Transferability-via-Information-Bottleneck-Constraints.
format Preprint
id arxiv_https___arxiv_org_abs_2406_05531
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Enhancing Adversarial Transferability via Information Bottleneck Constraints
Qi, Biqing
Gao, Junqi
Liu, Jianxing
Wu, Ligang
Zhou, Bowen
Machine Learning
Artificial Intelligence
From the perspective of information bottleneck (IB) theory, we propose a novel framework for performing black-box transferable adversarial attacks named IBTA, which leverages advancements in invariant features. Intuitively, diminishing the reliance of adversarial perturbations on the original data, under equivalent attack performance constraints, encourages a greater reliance on invariant features that contributes most to classification, thereby enhancing the transferability of adversarial attacks. Building on this motivation, we redefine the optimization of transferable attacks using a novel theoretical framework that centers around IB. Specifically, to overcome the challenge of unoptimizable mutual information, we propose a simple and efficient mutual information lower bound (MILB) for approximating computation. Moreover, to quantitatively evaluate mutual information, we utilize the Mutual Information Neural Estimator (MINE) to perform a thorough analysis. Our experiments on the ImageNet dataset well demonstrate the efficiency and scalability of IBTA and derived MILB. Our code is available at https://github.com/Biqing-Qi/Enhancing-Adversarial-Transferability-via-Information-Bottleneck-Constraints.
title Enhancing Adversarial Transferability via Information Bottleneck Constraints
topic Machine Learning
Artificial Intelligence
url https://arxiv.org/abs/2406.05531