Boosting the Transferability of Adversarial Examples Through Gradient Aggregation

Fuquan Gan, Yan Wo · IEEE Transactions on Information Forensics and Security · 2025

Deep neural networks(DNNs) have been demonstrated to be vulnerable to meticulously crafted adversarial examples. Transfer-based attacks do not require access to the target model’s information, have emerged as a substantial threat to the deployment of DNNs in real-world scenarios. Although considerable works have been conducted to enhance adversarial transferability from various perspectives, the transferability remains suboptimal. In this work, we propose a novel transfer-based attack, termed Gradient Aggregation Attack (GAA). Inspired by the observation that flatter local minima can improve transferability, GAA incorporates both the worst-aware loss and substitute loss into the objective function. The worst-aware loss represents the maximum loss within the neighborhood of the adversarial example, while the substitute loss quantifies the difference between the worst-aware loss and the empirical loss, serving as a measure of the flatness of the local minima region. By optimizing the empirical loss alongside these two losses, GAA is capable of generating adversarial examples within a flat local minimum region while simultaneously enhancing its flatness, ultimately surpassing all baselines. Specifically, since directly optimizing the worst-aware loss incurs substantial computation during adversarial example generation, we approximate the worst-aware loss with a first-order Taylor expansion to mitigate this computational cost. Via rigorous theoretical analysis and extensive experiments demonstrate that our proposed GAA method generates adversarial examples corresponding to flatter local minima regions. Compared to existing transfer-based attacks, GAA effectively enhances adversarial transferability, regardless of whether the model is a normally trained or an advanced defense model.

Read the paper · More papers on PaperTik