Boosting Transferability of Adversarial Examples by Joint Training and Dual Feature Mixup
At a glance
- Citations
- 0
- References
- 36
- Comments
- 0
Abstract
The transferability of adversarial examples is pivotal in black-box attacks on deep learning models. The existing transfer-based attacks typically rely on a single data augmentation technique, which hampers the diversity of generated adversarial examples. Additionally, applying a single adversarial noise generation path may impose limitations on the perturbation strength of the generated noise, thereby compromising the transferability of these examples. To address these issues, we propose a framework called Joint Training and Dual Feature Mixiup (JFM), which comprises the dual feature mixup module and joint training module. The dual feature mixup module performs feature mixing between benign and augmented images, enabling the comprehensive extraction of benign example features and enhancing the diversity of adversarial examples. Furthermore, the joint training module designs a dual-path prediction loss function that incorporates both the loss between mixed feature examples and benign examples, as well as the loss between augmented examples and benign examples, thereby enhancing the transferability of the generated examples. Empirical evaluation of the ImageNet-compatible dataset demonstrates that our JFM method exhibits superior attack capability and significantly outperforms state-of-the-art methods.
Publication details
- DOI
- 10.1109/trustcom63139.2024.00124
- OpenAlex
- W4409156331
- Document type
- conference-paper
- Language
- EN
- Last metadata update
Comments
Log in to join the discussion.