Boosting the Transferability of Adversarial Examples with Dynamic Gradient

Xianghui Fu, Xinghua Li · 2024

Deep neural networks (DNNs) are vulnerable to adversarial examples, which subtly alter benign images to mislead predictions. While white-box attacks are highly effective, black-box attacks suffer from limited transferability. To improve transferability, this paper introduces a dynamic gradient attack (DGA) that adaptively adjusts the update gradient by leveraging local data information. This approach, coupled with a smaller step size, stabilizes the optimization, reduces divergence risks, and enhances convergence smoothness. Experimental results on the ImageNet dataset show that DGA significantly outperforms existing gradient-based attacks in both standard and adversarially trained models.

Read the paper · More papers on PaperTik