Saved in:
Bibliographic Details
Main Authors: Liu, Hangyu, Peng, Bo, Ding, Pengxiang, Wang, Donglin
Format: Preprint
Published: 2025
Subjects:
Online Access:https://arxiv.org/abs/2504.14137
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909900901187584
author Liu, Hangyu
Peng, Bo
Ding, Pengxiang
Wang, Donglin
author_facet Liu, Hangyu
Peng, Bo
Ding, Pengxiang
Wang, Donglin
contents Compared to single-target adversarial attacks, multi-target attacks have garnered significant attention due to their ability to generate adversarial images for multiple target classes simultaneously. However, existing generative approaches for multi-target attacks primarily encode target labels into one-dimensional tensors, leading to a loss of fine-grained visual information and overfitting to model-specific features during noise generation. To address this gap, we first identify and validate that the semantic feature quality and quantity are critical factors affecting the transferability of targeted attacks: 1) Feature quality refers to the structural and detailed completeness of the implanted target features, as deficiencies may result in the loss of key discriminative information; 2) Feature quantity refers to the spatial sufficiency of the implanted target features, as inadequacy limits the victim model's attention to this feature. Based on these findings, we propose the 2D Tensor-Guided Adversarial Fusion (TGAF) framework, which leverages the powerful generative capabilities of diffusion models to encode target labels into two-dimensional semantic tensors for guiding adversarial noise generation. Additionally, we design a novel masking strategy tailored for the training process, ensuring that parts of the generated noise retain complete semantic information about the target class. Extensive experiments demonstrate that TGAF consistently surpasses state-of-the-art methods across various settings.
format Preprint
id arxiv_https___arxiv_org_abs_2504_14137
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Rethinking Target Label Conditioning in Adversarial Attacks: A 2D Tensor-Guided Generative Approach
Liu, Hangyu
Peng, Bo
Ding, Pengxiang
Wang, Donglin
Computer Vision and Pattern Recognition
Compared to single-target adversarial attacks, multi-target attacks have garnered significant attention due to their ability to generate adversarial images for multiple target classes simultaneously. However, existing generative approaches for multi-target attacks primarily encode target labels into one-dimensional tensors, leading to a loss of fine-grained visual information and overfitting to model-specific features during noise generation. To address this gap, we first identify and validate that the semantic feature quality and quantity are critical factors affecting the transferability of targeted attacks: 1) Feature quality refers to the structural and detailed completeness of the implanted target features, as deficiencies may result in the loss of key discriminative information; 2) Feature quantity refers to the spatial sufficiency of the implanted target features, as inadequacy limits the victim model's attention to this feature. Based on these findings, we propose the 2D Tensor-Guided Adversarial Fusion (TGAF) framework, which leverages the powerful generative capabilities of diffusion models to encode target labels into two-dimensional semantic tensors for guiding adversarial noise generation. Additionally, we design a novel masking strategy tailored for the training process, ensuring that parts of the generated noise retain complete semantic information about the target class. Extensive experiments demonstrate that TGAF consistently surpasses state-of-the-art methods across various settings.
title Rethinking Target Label Conditioning in Adversarial Attacks: A 2D Tensor-Guided Generative Approach
topic Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2504.14137