Pre-processing Transformation for Enhancing the Transferability of Adversarial Examples
Xiaotong Wang, Chunguang Huang, Fei Gao, Hai Ying Cheng · 2022 4th International Conference on Communications, Information System and Computer Engineering (CISCE) · 2022
Deep neural networks are susceptible to adversarial examples, which can cause misclassification of the models by adding some imperceptible perturbations to the original input images. Although most existing adversarial attack methods have achieved convincing success rates under white-box settings, they tend to exhibit weak transferability with the challenging black-box settings. Therefore, we propose a method based on input image pre-processing transformation named Shear & Pad Method (SPM) by optimizing the input diversity of the original images to generate adversarial examples. Meanwhile, it can alleviate the overfitting to improve the transferability of the adversarial examples. In addition, this method can be combined with related methods such as the family of fast gradient sign method to build stronger attack methods against the defense trained models. It can also be integrated into other transformation-based methods to generate more adversaries with better black-box transferability. Extensive experiments on the ImageNet dataset show that our proposed method has higher success rates than existing baseline attack methods both on a single model and an ensemble of models. Therefore, we hope that our method can be used as an effective benchmark for evaluating the robustness of deep network models.