IDATA:用于无限制对抗迁移攻击的可扩展可逆扩散模型
IDATA: Scalable Invertible Diffusion for Unrestricted Adversarial Transfer Attack
浏览论文内容
中文总结 AI 辅助
IDATA是一种用于无限制对抗迁移攻击的内存高效扩散框架,通过可逆扩散模块与低频约束模块提升攻击性能,在多基准测试中优于现有方法,可用于评估深度视觉模型黑盒鲁棒性。
中文摘要 AI 辅助
无限制对抗迁移攻击对于评估深度视觉模型的黑盒鲁棒性至关重要。基于扩散的攻击通过在隐空间的去噪轨迹上优化对抗扰动,已展现出良好的迁移能力与视觉不可感知性。然而,现有方法受限于两大挑战:内存密集型的多步反向传播,以及对中间隐变量的频率不敏感的扰动。为解决这些问题,我们提出IDATA,一种用于无限制对抗迁移攻击的内存高效型扩散框架。IDATA包含两个关键组件:可逆扩散模块(IDM)与低频约束模块(LFCM)。具体而言,IDM将扩散轨迹上的对抗优化重新表述为可逆过程,通过按需重建中间状态而非存储完整去噪链,实现了恒定内存的反向传播。此外,LFCM利用离散小波变换(DWT)将隐变量分解为低频与高频分量,将扰动限制在语义稳定的低频子空间中,从而在保持视觉不可感知性的同时提升了迁移能力。在多个基准数据集与多种模型架构上开展的大量实验表明,IDATA在攻击成功率、内存效率和视觉不可感知性方面始终优于现有最先进的基线方法。这些结果表明,IDATA是评估深度视觉模型黑盒鲁棒性的有潜力工具,代码可在指定网址获取。
英文摘要
Unrestricted adversarial transfer attacks are important for evaluating the black-box robustness of deep visual models. Diffusion-based attacks have shown promising transferability and visual imperceptibility by optimizing adversarial perturbations along denoising trajectories in latent space. However, existing methods are limited by two challenges: memory-intensive multistep backpropagation and frequency-agnostic perturbation over intermediate latents. To address these issues, we propose IDATA, a memory-efficient diffusion framework for unrestricted adversarial transfer attack. IDATA consists of two key components: an Invertible Diffusion Module (IDM) and a Low-Frequency Constraint Module (LFCM). Specifically, IDM reformulates adversarial optimization over diffusion trajectories as an invertible process, enabling constant-memory backpropagation through on-demand reconstruction of intermediate states instead of storing the full denoising chain. Moreover, LFCM leverages Discrete Wavelet Transform (DWT) to decompose latent variables into low- and high-frequency components, restricting perturbations to semantically stable low-frequency subspaces, thereby improving transferability while preserving visual imperceptibility. Extensive experiments on multiple benchmarks and diverse model architectures demonstrate that IDATA consistently outperforms state-of-the-art baselines in attack success rate, memory efficiency, and visual imperceptibility. These results suggest that IDATA is a promising tool for black-box robustness evaluation of deep visual models. Code is available at https://github.com/colourful-pan/IDATA.