arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.15115cs.CV

具有增强对抗样本迁移性的视角不变攻击

Perspective-Invariant Attack with Enhanced Transferability of Adversarial Examples

Kaisheng Liang, Yiming Cao, Bin Xiao

首次发表
浏览论文内容

中文总结 AI 辅助

针对对抗样本跨模型迁移性带来的安全威胁,提出视角不变攻击(PIA)及其扩展PIA-Mix,通过多自由度顶点采样策略提升对抗样本迁移性,实验显示其性能优于当前最优基于迁移的攻击方法。

中文摘要 AI 辅助

在代理深度神经网络(DNN)上生成的对抗样本通常能成功欺骗其他黑箱DNN模型,这种跨模型迁移性对实际应用中的DNN构成了严重安全威胁。输入变换技术被广泛用于通过增加输入图像的多样性来增强对抗迁移性,但现有方法主要依赖自由度(DOF)有限的局部操作,如分块洗牌和调整大小,忽略了因视角变化自然产生的全局视角变换。本研究提出视角不变攻击(PIA),引入多自由度顶点采样策略,系统覆盖从2自由度平移到8自由度投影映射的视角变换层级;通过生成几何多样性的输入变体,PIA有效降低了对抗扰动对代理模型的过拟合,从而提升对抗迁移性。我们进一步提出通用扩展方法PIA-Mix,其维护互补变换池,可高效结合视角变换与辅助方法以进一步提升迁移性。涉及多种DNN架构、先进防御机制及多模态大语言模型(LLM)的大量实验表明,PIA和PIA-Mix的性能优于当前最先进的基于迁移的攻击方法。

英文摘要

Adversarial examples generated on a surrogate deep neural network (DNN) can often successfully fool other black-box DNN models. This cross-model transferability poses serious security threats to DNNs in practical applications. Input transformation techniques are widely used to enhance adversarial transferability by increasing the diversity of input images. However, existing methods primarily rely on local operations with limited degrees of freedom (DOF), such as block-wise shuffling and resizing, overlooking global perspective transformations that naturally arise from viewpoint changes. In this work, we propose a Perspective-Invariant Attack (PIA), which introduces a multi-DOF vertex sampling strategy that systematically covers the perspective transformation hierarchy from 2-DOF translation to 8-DOF projective mapping. By generating geometrically diverse input variations, PIA effectively reduces overfitting of adversarial perturbations to the surrogate model, thereby improving adversarial transferability. We further propose PIA-Mix, a generic extension that maintains a complementary transformation pool and efficiently combines our perspective transformation with auxiliary methods for improved transferability. Extensive experiments involving various DNN architectures, advanced defense mechanisms, and multimodal large language models (LLMs) demonstrate that PIA and PIA-Mix outperform state-of-the-art transfer-based attacks.

发表机构

  • The Hong Kong Polytechnic University(香港理工大学)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑