Boosting the transferability of adversarial attacks with adaptive points selecting in temporal neighborhood

Hegui Zhu, Haoran Zheng, Ying Zhu, Xiaoyan Sui · Information Sciences · 2023

Deep neural networks are highly susceptible to imperceptible noise, even to the human eye. While high attack success rate has been achieved in white-box setting, the attack performance tends to decline in black-box environments. To address this challenge, this study introduces a novel adaptive points selecting iterative fast gradient sign method, named AI-FGSM, which leverages temporal neighborhoods to enhance transferability performance in black-box environments. AI-FGSM is unique in that it extracts gradients from additional points in the temporal neighborhood and adjusts the current gradient using previous gradients to maintain the updated trend's stability. This gradient correction enables faster optimization and restricts falling into local optima. Experimental results on the ImageNet dataset show that AI-FGSM outperforms advanced gradient-based attack methods such as MI-FGSM and NI-FGSM in terms of attack success rate and transferability. Moreover, in black-box environments, AI-FGSM achieves an average attack performance improvement of 44.2% for some models with adversarial training and 32.9% for several models without adversarial training. These results confirm the performance and effectiveness of AI-FGSM, underscoring its potential as a powerful tool for improving the transferability of adversarial attacks.

Read the paper · More papers on PaperTik