conference-paper

Boosting Transferability of Adversarial Examples by Joint Training and Dual Feature Mixup

Research footprint

At a glance

Citations
0
References
36
Comments
0
Paper overview

Abstract

The transferability of adversarial examples is pivotal in black-box attacks on deep learning models. The existing transfer-based attacks typically rely on a single data augmentation technique, which hampers the diversity of generated adversarial examples. Additionally, applying a single adversarial noise generation path may impose limitations on the perturbation strength of the generated noise, thereby compromising the transferability of these examples. To address these issues, we propose a framework called Joint Training and Dual Feature Mixiup (JFM), which comprises the dual feature mixup module and joint training module. The dual feature mixup module performs feature mixing between benign and augmented images, enabling the comprehensive extraction of benign example features and enhancing the diversity of adversarial examples. Furthermore, the joint training module designs a dual-path prediction loss function that incorporates both the loss between mixed feature examples and benign examples, as well as the loss between augmented examples and benign examples, thereby enhancing the transferability of the generated examples. Empirical evaluation of the ImageNet-compatible dataset demonstrates that our JFM method exhibits superior attack capability and significantly outperforms state-of-the-art methods.

Record transparency

Publication details

DOI
10.1109/trustcom63139.2024.00124
OpenAlex
W4409156331
Document type
conference-paper
Language
EN
Last metadata update
Community

Comments

Log in to join the discussion.

  1. No comments yet. Start the discussion.