Aug 2026· IEEE Transactions on Information Forensics and Security· Vol 21, pp. 6818-6831· 0 citations· 60 references
Computer Science
TL;DR
This work proposes a Perspective-Invariant Attack (PIA), which introduces a multi-DOF vertex sampling strategy that systematically covers the perspective transformation hierarchy from 2-DOF translation to 8-DOF projective mapping, and proposes PIA-Mix, a generic extension that maintains a complementary transformation pool and efficiently combines the authors' perspective transformation with auxiliary methods for improved transferability.
Abstract
Adversarial examples generated on a surrogate deep neural network (DNN) can often successfully fool other black-box DNN models. This cross-model transferability poses serious security threats to DNNs in practical applications. Input transformation techniques are widely used to enhance adversarial transferability by increasing the diversity of input images. However, existing methods primarily rely on local operations with limited degrees of freedom (DOF), such as block-wise shuffling and resizing, overlooking global perspective transformations that naturally arise from viewpoint changes. In this work, we propose a Perspective-Invariant Attack (PIA), which introduces a multi-DOF vertex sampling strategy that systematically covers the perspective transformation hierarchy from 2-DOF translation to 8-DOF projective mapping. By generating geometrically diverse input variations, PIA effectively reduces overfitting of adversarial perturbations to the surrogate model, thereby improving adversarial transferability. We further propose PIA-Mix, a generic extension that maintains a complementary transformation pool and efficiently combines our perspective transformation with auxiliary methods for improved transferability. Extensive experiments involving various DNN architectures, advanced defense mechanisms, and multimodal large language models (LLMs) demonstrate that PIA and PIA-Mix outperform state-of-the-art transfer-based attacks.
FDT-PC (Frequency Domain Transformation with Perceptual Constraints), a novel method that enhances adversarial transferability across different model architectures, is proposed, which achieves superior black-box attack performance on both CNNs and Vision Transformers, outperforming existing state-of-the-art input transformation methods.
Bo Li, Li Tang, Xin Jin et al.· ACM Transactions on Multimed...· 0 citations
Extensive experiments demonstrate that IDATA consistently outperforms state-of-the-art baselines in attack success rate, memory efficiency, and visual imperceptibility, suggesting that IDATA is a promising tool for black-box robustness evaluation of deep visual models.
Yi Pan, Jun-Jie Huang, Tianrui Liu et al.· 0 citations
Empirical support is provided for the utility of structure-aware perturbation refinement in improving black-box adversarial transferability across heterogeneous visual architectures.
Qi-Rui Lu, Liansong Zong, Fu-Ran Liu et al.· Neural Networks· 0 citations
This approach improves transferability by combining different parameter initializations to generate a diversified set of surrogate models and integrates an adversarial makeup technique that generates adversarial disguises from reference images, thereby further boosting the attack's effectiveness.
This work proposes BMAT (Bilevel-Minimax Adversarial Transfer), an integrated bottom-up solver that combines a Soft Weight Modulator and an Implicit Gradient Approximator to enable ternary coupling among initialization, surrogate adaptation, and perturbation optimization.
Dual Modular Redundancy (DMR) and Triple Modular Redundancy (TMR) are commonly used methods for providing fault detection and/or tolerance in safety-critical systems by incorporating redundant – and often diverse – components. However, these systems can still be susceptible to adversarial attacks that may deceive AI models, potentially leading to severe consequences. In this paper, we introduce enhanced DMR and TMR strategies for image-based object detection, leveraging image transformations during inference to help reduce the impact of adversarial inputs, while preserving the inherent advantages of diverse redundancy for safety purposes. Experimental results demonstrate that our approach significantly improves robustness under adversarial conditions, achieving up to 12.9% and 12.2% higher accuracy than state-of-the-art solutions in DMR and TMR configurations, respectively, when attacks are individually crafted for each image. Furthermore, against universal adversarial attacks, our solution achieves even greater accuracy gains, with up to 26.8% and 26.0% higher accuracy in DMR and TMR configurations, respectively.
Martí Caro, Axel Brando, Jaume Abella· ACM Transactions on Design A...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.