Boosting adversarial attacks with attention-guided luminance perturbation
Abstract
Deep Neural Networks (DNNs) are vulnerable to adversarial examples generated by adding human-imperceptible perturbations to benign inputs. Moreover, the transferability of adversarial examples enables effective black-box attacks across different models. However, existing attack methods typically generate spatially dense perturbations and distribute them indiscriminately across RGB channels, leading to redundant perturbation patterns that reduce perturbation efficiency and perceptual quality. To address this issue, we propose Attention-aware Luminance Attack (ALA), a simple yet effective framework that reduces perturbation redundancy through structured constraints. Specifically, ALA consists of two key components: attention-guided spatial masking, which leverages Grad-CAM++ attention maps to constrain perturbations within class-relevant regions, and luminance channel projection, which preserves perturbations only in the luminance channel of the YUV space while discarding the chrominance channels. By jointly enforcing spatial selectivity and channel sparsity, the proposed method generates more compact and semantically aligned perturbations. Experimental results demonstrate that ALA effectively enhances both transfer attack capability and visual quality.