跳到主要导航 跳到搜索 跳到主要内容

Improving Transferability of Adversarial Attacks via Frequency-Consistent Regularization

  • Beihang University
  • Science & Technology on Reliability & Environmental Engineering Laboratory

科研成果: 期刊稿件文章同行评审

摘要

Adversarial examples have revealed the vulnerability of deep neural networks, and their transferability makes black-box attacks particularly concerning. However, perturbations crafted on a surrogate model often do not remain sufficiently effective on unseen target models. In this paper, we revisit this issue from a frequency-domain perspective and observe that perturbation optimization can become overly dependent on specific spectral patterns, which weakens cross-model transfer. To address this problem, we propose frequency-consistent regularization (FCR), a simple plug-in strategy that can be combined with existing iterative attacks. FCR introduces multiple low-frequency preserving views with randomly sampled frequency ranges at each iteration and optimizes perturbations across these varied views. In this way, the generated perturbations are less tied to a specific frequency configuration and show improved transferability. Experimental results show that FCR consistently improves the transfer performance of various iterative attacks. The improvement is observed not only in standard target models but also in adversarially trained models, where the gain is often more pronounced.

源语言英语
文章编号3748
期刊Applied Sciences (Switzerland)
16
8
DOI
出版状态已出版 - 4月 2026

指纹

探究 'Improving Transferability of Adversarial Attacks via Frequency-Consistent Regularization' 的科研主题。它们共同构成独一无二的指纹。

引用此