跳到主要导航 跳到搜索 跳到主要内容

Frequency Domain Model Augmentation for Adversarial Attack

  • Yuyang Long
  • , Qilong Zhang
  • , Boheng Zeng
  • , Lianli Gao
  • , Xianglong Liu
  • , Jian Zhang
  • , Jingkuan Song*
  • *此作品的通讯作者
  • University of Electronic Science and Technology of China
  • Hunan University

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

For black-box attacks, the gap between the substitute model and the victim model is usually large, which manifests as a weak attack performance. Motivated by the observation that the transferability of adversarial examples can be improved by attacking diverse models simultaneously, model augmentation methods which simulate different models by using transformed images are proposed. However, existing transformations for spatial domain do not translate to significantly diverse augmented models. To tackle this issue, we propose a novel spectrum simulation attack to craft more transferable adversarial examples against both normally trained and defense models. Specifically, we apply a spectrum transformation to the input and thus perform the model augmentation in the frequency domain. We theoretically prove that the transformation derived from frequency domain leads to a diverse spectrum saliency map, an indicator we proposed to reflect the diversity of substitute models. Notably, our method can be generally combined with existing attacks. Extensive experiments on the ImageNet dataset demonstrate the effectiveness of our method, e.g., attacking nine state-of-the-art defense models with an average success rate of 95.4%. Our code is available in https://github.com/yuyang-long/SSA.

源语言英语
主期刊名Computer Vision – ECCV 2022 - 17th European Conference, Proceedings
编辑Shai Avidan, Gabriel Brostow, Moustapha Cissé, Giovanni Maria Farinella, Tal Hassner
出版商Springer Science and Business Media Deutschland GmbH
549-566
页数18
ISBN(印刷版)9783031197710
DOI
出版状态已出版 - 2022
活动17th European Conference on Computer Vision, ECCV 2022 - Tel Aviv, 以色列
期限: 23 10月 202227 10月 2022

出版系列

姓名Lecture Notes in Computer Science
13664 LNCS
ISSN(印刷版)0302-9743
ISSN(电子版)1611-3349

会议

会议17th European Conference on Computer Vision, ECCV 2022
国家/地区以色列
Tel Aviv
时期23/10/2227/10/22

指纹

探究 'Frequency Domain Model Augmentation for Adversarial Attack' 的科研主题。它们共同构成独一无二的指纹。

引用此