Adaptive Image Transformations for Transfer-based Adversarial Attack
arXiv:2111.13844
Abstract
Adversarial attacks provide a good way to study the robustness of deep learning models. One category of methods in transfer-based black-box attack utilizes several image transformation operations to improve the transferability of adversarial examples, which is effective, but fails to take the specific characteristic of the input image into consideration. In this work, we propose a novel architecture, called Adaptive Image Transformation Learner (AITL), which incorporates different image transformation operations into a unified framework to further improve the transferability of adversarial examples. Unlike the fixed combinational transformations used in existing works, our elaborately designed transformation learner adaptively selects the most effective combination of image transformations specific to the input image. Extensive experiments on ImageNet demonstrate that our method significantly improves the attack success rates on both normally trained models and defense models under various settings.
34 pages, 7 figures, 11 tables. Accepted by ECCV2022
References in corpus (9)
- Rethinking Atrous Convolution for Semantic Image Segmentation
- ZOO: Zeroth Order Optimization based Black-box Attacks to Deep Neural Networks without Training Substitute Models
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks
- Fast is better than free: Revisiting adversarial training
- On the Convergence and Robustness of Adversarial Training
- Skip Connections Matter: On the Transferability of Adversarial Examples Generated with ResNets
- Certified Robustness for Top-k Predictions against Adversarial Perturbations via Randomized Smoothing
- Boosting Adversarial Transferability through Enhanced Momentum
- Backpropagating Linearly Improves Transferability of Adversarial Examples