Improving Transferable Targeted Attacks with Feature Tuning Mixup

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Liang, Kaisheng, Dai, Xuelong, Li, Yanjie, Wang, Dong, Xiao, Bin
Formato: Preprint
Publicado: 2024
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866910891052630016
author Liang, Kaisheng
Dai, Xuelong
Li, Yanjie
Wang, Dong
Xiao, Bin
author_facet Liang, Kaisheng
Dai, Xuelong
Li, Yanjie
Wang, Dong
Xiao, Bin
contents Deep neural networks (DNNs) exhibit vulnerability to adversarial examples that can transfer across different DNN models. A particularly challenging problem is developing transferable targeted attacks that can mislead DNN models into predicting specific target classes. While various methods have been proposed to enhance attack transferability, they often incur substantial computational costs while yielding limited improvements. Recent clean feature mixup methods use random clean features to perturb the feature space but lack optimization for disrupting adversarial examples, overlooking the advantages of attack-specific perturbations. In this paper, we propose Feature Tuning Mixup (FTM), a novel method that enhances targeted attack transferability by combining both random and optimized noises in the feature space. FTM introduces learnable feature perturbations and employs an efficient stochastic update strategy for optimization. These learnable perturbations facilitate the generation of more robust adversarial examples with improved transferability. We further demonstrate that attack performance can be enhanced through an ensemble of multiple FTM-perturbed surrogate models. Extensive experiments on the ImageNet-compatible dataset across various DNN models demonstrate that our method achieves significant improvements over state-of-the-art methods while maintaining low computational cost.
format Preprint
id arxiv_https___arxiv_org_abs_2411_15553
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Improving Transferable Targeted Attacks with Feature Tuning Mixup
Liang, Kaisheng
Dai, Xuelong
Li, Yanjie
Wang, Dong
Xiao, Bin
Computer Vision and Pattern Recognition
Deep neural networks (DNNs) exhibit vulnerability to adversarial examples that can transfer across different DNN models. A particularly challenging problem is developing transferable targeted attacks that can mislead DNN models into predicting specific target classes. While various methods have been proposed to enhance attack transferability, they often incur substantial computational costs while yielding limited improvements. Recent clean feature mixup methods use random clean features to perturb the feature space but lack optimization for disrupting adversarial examples, overlooking the advantages of attack-specific perturbations. In this paper, we propose Feature Tuning Mixup (FTM), a novel method that enhances targeted attack transferability by combining both random and optimized noises in the feature space. FTM introduces learnable feature perturbations and employs an efficient stochastic update strategy for optimization. These learnable perturbations facilitate the generation of more robust adversarial examples with improved transferability. We further demonstrate that attack performance can be enhanced through an ensemble of multiple FTM-perturbed surrogate models. Extensive experiments on the ImageNet-compatible dataset across various DNN models demonstrate that our method achieves significant improvements over state-of-the-art methods while maintaining low computational cost.
title Improving Transferable Targeted Attacks with Feature Tuning Mixup
topic Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2411.15553