2026· IEEE Transactions on Information Forensics and Security· Vol 21, pp. 8431-8446· 0 citations· 40 references
Abstract
Understanding adversarial attacks is crucial for the secure deployment of visual recognition systems. While ensemble attacks combine the strengths of transfer-based and query-based methods to generate highly transferable adversarial examples, their practicality is often limited in real-world scenarios where the number of queries is restricted. In this paper, we propose a novel frequency-driven ensemble adversarial attack, termed WPEBA, that enables efficient black-box attacks with a minimal number of queries. We first apply wavelet packet decomposition (WPD) to decompose images into frequency sub-bands. Driven by a unified ensemble loss across multiple surrogate models, we adaptively adjust frequency-band weights using internal gradient feedback and jointly generate gradient-based and block-based perturbations in the frequency domain. The perturbed components are then reconstructed into the spatial domain via inverse WPD to produce adversarial examples for querying the target model. Finally, we utilize the query feedback from the target model to dynamically update the surrogate-model weights, guiding the attack in subsequent iterations. Extensive evaluations demonstrate that WPEBA achieves an average attack success rate of nearly 99% with merely one or two queries across six distinct standard architectures. Furthermore, it maintains effective attack performance against models equipped with robust defenses and the Google Cloud Vision API. Overall, our method provides a new and practical approach for evaluating general model robustness.
Neural networks, both convolution or transformer based, are essential for modern computer vision systems. However, they are vulnerable to small perturbations, almost imperceptible to humans, which significantly alter the model's prediction. These adversarial attacks are often considered to be a significant threat to th...
F. Krone, Elena Hoemann, Sven Hallerbach· 0 citations
This paper proposes a methodology for crafting principled frequency-based adversarial attacks, via a dedicated optimization framework, and proves that the attacks emerge as weighted $\ell_2$-projections onto this set, yielding a general and controlled attack generation mechanism.
Vicky Kouni, Stelios Perrakis, Francis R. Bach et al.· 0 citations
Extensive experiments demonstrate that IDATA consistently outperforms state-of-the-art baselines in attack success rate, memory efficiency, and visual imperceptibility, suggesting that IDATA is a promising tool for black-box robustness evaluation of deep visual models.
Yi Pan, Jun-Jie Huang, Tianrui Liu et al.· 0 citations
Infrared and visible image fusion (IVIF) integrates complementary multi-modal information, yet existing methods typically overlook deliberate adversarial attacks. To enhance model robustness in adversarial environments, we propose a novel adversarial attack resilient network, called Frequency-Aware and Dynamic Curve Ne...
Peng-Cheng Gao, Sheng-Yue Huang· Journal of King Saud Univers...· 0 citations
Deep Neural Networks (DNNs) remain vulnerable to adversarial perturbations, raising significant concerns in image processing applications, particularly in high-stakes domains such as medical imaging and security-critical systems. Most existing defense strategies are limited by domain specificity, architectural dependen...
Syamantak Sarkar, Nirmal Joseph, Sudhish N. George et al.· IEEE Transactions on Image P...· 0 citations