发表机构
National University of Defense Technology; Academy of Military Science; Sun Yat-sen University; Hefei Institute of Technology(国防科技大学; 军事科学院; 中山大学; 合肥工业大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本文提出隐蔽迁移攻击ST,通过原始-对偶正则化包装器在固定预算下解锁强迁移攻击的潜在不可感知性优势,扩展帕累托前沿,同时保持或提升攻击成功率。
AI 中文摘要
可迁移的对抗攻击可以说是最实用的黑盒威胁模型。在相同的扰动预算下,更强的迁移攻击能达到更高的攻击成功率(ASR),但其不可感知性也往往随之下降。在这种固定预算协议下,迁移性和不可感知性因此似乎相互权衡。我们认为,这种冲突是固定预算评估的产物,而非内在的权衡。当攻击在通过扫描ε获得的ASR-不可感知性帕累托前沿上进行比较时,更强的迁移攻击在匹配的ASR下已经比更弱的攻击实现了更好的不可感知性。为了利用这一潜在优势,我们引入了隐蔽迁移攻击ST,这是一种即插即用的原始-对偶包装器,它将L∞饱和正则化器添加到标准约束目标中,并通过两步原始-对偶更新来解决:对扰动进行投影原始步骤,同时对通过Fenchel对偶吸收正则化器的对偶变量进行L1球投影,无需辅助模型或手工制作的感知先验。实验上,ST在不同基础攻击和额外替代架构上扩展了帕累托前沿。在ε=16/255时,相对于每个基础攻击,平均不可感知性增益在LPIPS上为17%,在NIQE上为14%,同时ASR保持不变或有所提高。在匹配的高ASR水平下,最强的ST变体进一步帕累托支配专门针对隐蔽性的迁移攻击,证实了强迁移攻击的潜在不可感知性优势可以通过原始-对偶优化包装器解锁,而无需牺牲迁移性。代码将在\this https URL提供。
英文摘要
Transferable adversarial attacks are arguably the most practical black-box threat model. Under the same perturbation budget, stronger transfer attacks attain higher attack success rate (ASR), yet their imperceptibility also tends to degrade. Under such a fixed-budget protocol, transferability and imperceptibility therefore appear to trade off against each other. We argue that this conflict is an artifact of fixed-budget evaluation, not an intrinsic trade-off. When attacks are compared on the ASR--imperceptibility Pareto frontier obtained by sweeping $ε$, stronger transfer attacks already attain better imperceptibility at matched ASR than weaker ones. To exploit this latent advantage, we introduce the stealthy transfer attack ST, a plug-in primal-dual wrapper that adds an $L_\infty$ saturation regularizer to the standard constrained objective and resolves it through a two-step primal-dual update: a projected primal step on the perturbation coupled with an $L_1$-ball projection on a dual variable that absorbs the regularizer through Fenchel duality, requiring no auxiliary models or handcrafted perceptual priors. Empirically, ST extends the Pareto frontier across different base attacks and additional surrogate architectures. At $ε{=}16/255$, average imperceptibility gains over each base attack are $17\%$ on LPIPS and $14\%$ on NIQE while ASR is preserved or improved. At matched high-ASR levels, the strongest ST variants further Pareto-dominate dedicated stealth-oriented transfer attacks, confirming that the latent imperceptibility advantage of strong transfer attacks can be unlocked by a primal-dual optimization wrapper without sacrificing transferability. Code will be made available at \url{https://github.com/AndssY/ST}.
Comments17 pages, 10 figures