The Enhanced Deformation Attack (EDA), which estimates attack gradients over stochastically transformed views of the current adversarial image, achieves the highest mean attack success rate (ASR) on ViT targets for all four CNN sources, outperforming the strongest source-specific baseline.
Abstract
Adversarial examples generated on convolutional neural network (CNN) surrogates often transfer less effectively to vision transformer (ViT) targets than to CNN targets, creating a cross-architecture bottleneck for transfer-based black-box attacks. Existing input-transformation attacks diversify gradient estimation, yet the evaluated baselines still exhibit substantial CNN-to-ViT transfer gaps, motivating a deformation strategy that varies both control-point geometry and boundary support. To address this limitation, this paper proposes the Enhanced Deformation Attack (EDA), which estimates attack gradients over stochastically transformed views of the current adversarial image. Each view samples either a full control-point grid with movable boundary points or an interior center grid, and the displaced control points are remapped to a reflection-padded canvas before thin-plate spline (TPS) resampling. Gaussian noise or brightness adjustment provides complementary appearance variation. All transformations are confined to gradient estimation, so the final adversarial example remains in the original coordinate system and satisfies the prescribed ℓ∞ perturbation budget. On the ImageNet-Compatible dataset, EDA achieves the highest mean attack success rate (ASR) on ViT targets for all four CNN sources, outperforming the strongest source-specific baseline by 5.8, 11.2, 8.7, and 8.0 percentage points under ResNet-18, Inception-v3, Inception-v4, and Inception-ResNet-v2, respectively. The gains also persist on the full ImageNet validation set and ImageNet-V2 across all evaluated source and target groups. Additional evaluations across four perturbation budgets, targeted settings, five random seeds, defended models, and modern robust models further support the stability and scope of the observed transfer gains. The source code is publicly available at https://github.com/wjc2400136/EDA.
Transfer-based black-box attacks are an important tool for evaluating deployed vision models, yet adversarial examples generated from Vision Transformer (ViT) surrogates often exhibit limited cross-architecture transferability. Existing momentum-based attacks are effective for convolutional neural network (CNN) surroga...
Lei Lu, Run-Han Yao, Qing-He Du et al.· 2026 International Conferenc...· 0 citations
Deep Neural Networks (DNNs) are vulnerable to adversarial examples generated by adding human-imperceptible perturbations to benign inputs. Moreover, the transferability of adversarial examples enables effective black-box attacks across different models. However, existing attack methods typically generate spatially dens...
Zi-Han Huang· International Conference on...· 0 citations
Pixel diffusion models generate RGB images directly, avoiding the bottleneck of an autoencoder, yet their outputs still systematically underrepresent fine-scale natural-image statistics. We show that adversarial learning provides an effective post-training correction for this deficiency. Starting from a pretrained mode...
Xin Lin, Zhi-Fei Zhang, Yu-Qian Zhou et al.· 0 citations
Transferable adversarial attacks provide an important means of evaluating the black-box security of remote sensing scene classification models. However, the existing spatial input transformations commonly rely on predefined block shapes and limited partition granularities, providing insufficient coverage of the diverse...
Rui Zhang, Jie Wang, Wen-Jun Hu et al.· IEEE Geoscience and Remote S...· 0 citations
Season, a spectrum-aware orthogonal gradient refinement framework for L-infinity transfer attacks against black-box target models on ImageNet, using a white-box surrogate to improve transfer success rate.
Optimize Deep Learning–based Adversarial Defense Mechanism (ODL-ADM) is proposed in this work, which projects adversarial samples into an immune feature space that is both discriminative and resistant to perturbations.
Sheilla Ann Bangoy Pacheco, Mahesh Goyani, Jayzel P. Bangoy et al.· ITEGAM- Journal of Engineeri...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.