Skip to content

WPEBA: A Novel Ensemble Black-Box Adversarial Attack for Visual Recognition Systems via Wavelet Packet Decomposition

2026 · IEEE Transactions on Information Forensics and Security · Vol 21, pp. 8431-8446 · 0 citations · 40 references

Abstract

Understanding adversarial attacks is crucial for the secure deployment of visual recognition systems. While ensemble attacks combine the strengths of transfer-based and query-based methods to generate highly transferable adversarial examples, their practicality is often limited in real-world scenarios where the number of queries is restricted. In this paper, we propose a novel frequency-driven ensemble adversarial attack, termed WPEBA, that enables efficient black-box attacks with a minimal number of queries. We first apply wavelet packet decomposition (WPD) to decompose images into frequency sub-bands. Driven by a unified ensemble loss across multiple surrogate models, we adaptively adjust frequency-band weights using internal gradient feedback and jointly generate gradient-based and block-based perturbations in the frequency domain. The perturbed components are then reconstructed into the spatial domain via inverse WPD to produce adversarial examples for querying the target model. Finally, we utilize the query feedback from the target model to dynamically update the surrogate-model weights, guiding the attack in subsequent iterations. Extensive evaluations demonstrate that WPEBA achieves an average attack success rate of nearly 99% with merely one or two queries across six distinct standard architectures. Furthermore, it maintains effective attack performance against models equipped with robust defenses and the Google Cloud Vision API. Overall, our method provides a new and practical approach for evaluating general model robustness.

View source

Similar papers

#machine learning Preprint Sep 2026

Reinforcement Learning Inspired Black-box Adversarial Attacks for Computer Vision

Neural networks, both convolution or transformer based, are essential for modern computer vision systems. However, they are vulnerable to small perturbations, almost imperceptible to humans, which significantly alter the model's prediction. These adversarial attacks are often considered to be a significant threat to th...

F. Krone, Elena Hoemann, Sven Hallerbach · 0 citations
#machine learning Preprint Sep 2026

Frame the adversary: a structure-aware attack methodology

This paper proposes a methodology for crafting principled frequency-based adversarial attacks, via a dedicated optimization framework, and proves that the attacks emerge as weighted $\ell_2$-projections onto this set, yielding a general and controlled attack generation mechanism.

Vicky Kouni, Stelios Perrakis, Francis R. Bach et al. · 0 citations
Preprint Aug 2026

IDATA: Scalable Invertible Diffusion for Unrestricted Adversarial Transfer Attack

Extensive experiments demonstrate that IDATA consistently outperforms state-of-the-art baselines in attack success rate, memory efficiency, and visual imperceptibility, suggesting that IDATA is a promising tool for black-box robustness evaluation of deep visual models.

Yi Pan, Jun-Jie Huang, Tianrui Liu et al. · 0 citations
Open access Sep 2026

FDCNet: frequency-aware and dynamic curve network for adversarially robust infrared and visible image fusion

Infrared and visible image fusion (IVIF) integrates complementary multi-modal information, yet existing methods typically overlook deliberate adversarial attacks. To enhance model robustness in adversarial environments, we propose a novel adversarial attack resilient network, called Frequency-Aware and Dynamic Curve Ne...

Peng-Cheng Gao, Sheng-Yue Huang · 0 citations
Sep 2026

Seeing Through Threats: Adversarial Detection Through Explainability (ADEx)

Deep Neural Networks (DNNs) remain vulnerable to adversarial perturbations, raising significant concerns in image processing applications, particularly in high-stakes domains such as medical imaging and security-critical systems. Most existing defense strategies are limited by domain specificity, architectural dependen...

Syamantak Sarkar, Nirmal Joseph, Sudhish N. George et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.