Using dynamically changing step sizes to increase the success rate of adversarial attacks

Qidong Huang, Leiji Lu, Jun Chen, Lei Bao · 2024

In recent years, it has been widely believed that deep neural networks are vulnerability to adversarial sample attacks, especially under the white-box attack mode, where the attack effects are quite evident. However, experiments have shown that adversarial samples generated in white-box mode can easily fall into local optima quickly, and their attack transferability is relatively poor. Momentum-based methods can effectively skip local optima by accumulating past gradients, thereby enhancing the transferability of adversarial samples. In the process of studying adversarial attack patterns, we noticed that the transferability of adversarial samples generated by the Iterative Fast Gradient Sign Method (I-FGSM) decreases with the increase of iteration times. Based on this phenomenon, we believe that the adversarial perturbation information close to the clean sample, especially its directional information, is more effective in improving the transferability of adversarial samples. Therefore, we propose a dynamically changing step size strategy, which fully utilize the adversarial information of the original sample under constraint conditions. The strategy proposed in this paper can be easily combined with existing adversarial attack methods to improve the transferability of adversarial samples. Experiments show that the method proposed in this paper can be combined with data augmentation methods and other methods to effectively improve the attack transferability of adversarial samples from the original method.

Read the paper · More papers on PaperTik