Leveraging Information Consistency in Frequency and Spatial Domain for Adversarial Attacks

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Jin, Zhibo, Zhang, Jiayu, Zhu, Zhiyu, Wang, Xinyi, Huang, Yiyun, Chen, Huaming
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866910574677327872
author Jin, Zhibo
Zhang, Jiayu
Zhu, Zhiyu
Wang, Xinyi
Huang, Yiyun
Chen, Huaming
author_facet Jin, Zhibo
Zhang, Jiayu
Zhu, Zhiyu
Wang, Xinyi
Huang, Yiyun
Chen, Huaming
contents Adversarial examples are a key method to exploit deep neural networks. Using gradient information, such examples can be generated in an efficient way without altering the victim model. Recent frequency domain transformation has further enhanced the transferability of such adversarial examples, such as spectrum simulation attack. In this work, we investigate the effectiveness of frequency domain-based attacks, aligning with similar findings in the spatial domain. Furthermore, such consistency between the frequency and spatial domains provides insights into how gradient-based adversarial attacks induce perturbations across different domains, which is yet to be explored. Hence, we propose a simple, effective, and scalable gradient-based adversarial attack algorithm leveraging the information consistency in both frequency and spatial domains. We evaluate the algorithm for its effectiveness against different models. Extensive experiments demonstrate that our algorithm achieves state-of-the-art results compared to other gradient-based algorithms. Our code is available at: https://github.com/LMBTough/FSA.
format Preprint
id arxiv_https___arxiv_org_abs_2408_12670
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Leveraging Information Consistency in Frequency and Spatial Domain for Adversarial Attacks
Jin, Zhibo
Zhang, Jiayu
Zhu, Zhiyu
Wang, Xinyi
Huang, Yiyun
Chen, Huaming
Machine Learning
Artificial Intelligence
Adversarial examples are a key method to exploit deep neural networks. Using gradient information, such examples can be generated in an efficient way without altering the victim model. Recent frequency domain transformation has further enhanced the transferability of such adversarial examples, such as spectrum simulation attack. In this work, we investigate the effectiveness of frequency domain-based attacks, aligning with similar findings in the spatial domain. Furthermore, such consistency between the frequency and spatial domains provides insights into how gradient-based adversarial attacks induce perturbations across different domains, which is yet to be explored. Hence, we propose a simple, effective, and scalable gradient-based adversarial attack algorithm leveraging the information consistency in both frequency and spatial domains. We evaluate the algorithm for its effectiveness against different models. Extensive experiments demonstrate that our algorithm achieves state-of-the-art results compared to other gradient-based algorithms. Our code is available at: https://github.com/LMBTough/FSA.
title Leveraging Information Consistency in Frequency and Spatial Domain for Adversarial Attacks
topic Machine Learning
Artificial Intelligence
url https://arxiv.org/abs/2408.12670