Our new X account is live! Follow @wizwand_team for updates
WorkDL logo mark

Improving the Transferability of Adversarial Examples with Resized-Diverse-Inputs, Diversity-Ensemble and Region Fitting

About

We introduce a three stage pipeline: resized-diverse-inputs (RDIM), diversity-ensemble (DEM) and region fitting, that work together to generate transferable adversarial examples. We first explore the internal relationship between existing attacks, and propose RDIM that is capable of exploiting this relationship. Then we propose DEM, the multi-scale version of RDIM, to generate multi-scale gradients. After the first two steps we transform value fitting into region fitting across iterations. RDIM and region fitting do not require extra running time and these three steps can be well integrated into other attacks. Our best attack fools six black-box defenses with a 93% success rate on average, which is higher than the state-of-the-art gradient-based attacks. Besides, we rethink existing attacks rather than simply stacking new methods on the old ones to get better performance. It is expected that our findings will serve as the beginning of exploring the internal relationship between attack methods. Codes are available at https://github.com/278287847/DEM.

Junhua Zou, Zhisong Pan, Junyang Qiu, Xin Liu, Ting Rui, Wei Li• 2021

Related benchmarks

TaskDatasetResultRank
Targeted Adversarial AttackImageNet
VGG-16 Score66.9
39
Targeted Adversarial AttackImageNet
Dense-121 Score5.2
31
Targeted Transfer AttackImageNet (val)--
25
Targeted Adversarial AttackImageNet (val)
ViT Performance20
23
Targeted Adversarial AttackImageNet-Compatible
Success Rate (adv-RN-50)98.8
14
Targeted Adversarial AttackImageNet
VGG-16 Robust Accuracy3.5
10
Targeted Adversarial AttackImageNet RN-50 Source 1k (val)
ViT Performance Score0.7
10
Targeted Adversarial AttackImageNet (test)
Inference Time (s)1.76
9
Targeted Adversarial AttackImageNet
VGG-16 Score75.3
9
Targeted AttackImageNet-Compatible (val)
VGG-16 Score0.035
7
Showing 10 of 11 rows

Other info

Follow for update