Skip to content
Open access

Perspective-Invariant Attack With Enhanced Transferability of Adversarial Examples

Aug 2026 · IEEE Transactions on Information Forensics and Security · Vol 21, pp. 6818-6831 · 0 citations · 60 references
Computer Science

TL;DR

This work proposes a Perspective-Invariant Attack (PIA), which introduces a multi-DOF vertex sampling strategy that systematically covers the perspective transformation hierarchy from 2-DOF translation to 8-DOF projective mapping, and proposes PIA-Mix, a generic extension that maintains a complementary transformation pool and efficiently combines the authors' perspective transformation with auxiliary methods for improved transferability.

Abstract

Adversarial examples generated on a surrogate deep neural network (DNN) can often successfully fool other black-box DNN models. This cross-model transferability poses serious security threats to DNNs in practical applications. Input transformation techniques are widely used to enhance adversarial transferability by increasing the diversity of input images. However, existing methods primarily rely on local operations with limited degrees of freedom (DOF), such as block-wise shuffling and resizing, overlooking global perspective transformations that naturally arise from viewpoint changes. In this work, we propose a Perspective-Invariant Attack (PIA), which introduces a multi-DOF vertex sampling strategy that systematically covers the perspective transformation hierarchy from 2-DOF translation to 8-DOF projective mapping. By generating geometrically diverse input variations, PIA effectively reduces overfitting of adversarial perturbations to the surrogate model, thereby improving adversarial transferability. We further propose PIA-Mix, a generic extension that maintains a complementary transformation pool and efficiently combines our perspective transformation with auxiliary methods for improved transferability. Extensive experiments involving various DNN architectures, advanced defense mechanisms, and multimodal large language models (LLMs) demonstrate that PIA and PIA-Mix outperform state-of-the-art transfer-based attacks.

Read PDF

Similar papers

Aug 2026

FDT-PC: Enhancing Adversarial Transferability through Frequency Domain Transformation and Perceptual Constraints

FDT-PC (Frequency Domain Transformation with Perceptual Constraints), a novel method that enhances adversarial transferability across different model architectures, is proposed, which achieves superior black-box attack performance on both CNNs and Vision Transformers, outperforming existing state-of-the-art input transformation methods.

Bo Li, Li Tang, Xin Jin et al. · 0 citations
Preprint Aug 2026

IDATA: Scalable Invertible Diffusion for Unrestricted Adversarial Transfer Attack

Extensive experiments demonstrate that IDATA consistently outperforms state-of-the-art baselines in attack success rate, memory efficiency, and visual imperceptibility, suggesting that IDATA is a promising tool for black-box robustness evaluation of deep visual models.

Yi Pan, Jun-Jie Huang, Tianrui Liu et al. · 0 citations
Aug 2026

Adversarial face camouflage based on multi-parameter enhancement.

This approach improves transferability by combining different parameter initializations to generate a diversified set of surrogate models and integrates an adversarial makeup technique that generates adversarial disguises from reference images, thereby further boosting the attack's effectiveness.

DaPeng Men, Jingyu Wang, Xiaolin Zhang et al. · 0 citations
Preprint Aug 2026

Learning with Bilevel-Minimax Optimization for Efficient and Reliable Transfer Attacks

This work proposes BMAT (Bilevel-Minimax Adversarial Transfer), an integrated bottom-up solver that combines a Soft Weight Modulator and an Implicit Gradient Approximator to enable ternary coupling among initialization, surrogate adaptation, and perturbation optimization.

Yaohua Liu, Yifan Guo, Jiaxin Gao · 0 citations
Jul 2026

Two-for-One: Image-based Transformations to Mitigate Adversarial Attacks and Random Faults at Once in Safety-critical AI Systems

Dual Modular Redundancy (DMR) and Triple Modular Redundancy (TMR) are commonly used methods for providing fault detection and/or tolerance in safety-critical systems by incorporating redundant – and often diverse – components. However, these systems can still be susceptible to adversarial attacks that may deceive AI models, potentially leading to severe consequences. In this paper, we introduce enhanced DMR and TMR strategies for image-based object detection, leveraging image transformations during inference to help reduce the impact of adversarial inputs, while preserving the inherent advantages of diverse redundancy for safety purposes. Experimental results demonstrate that our approach significantly improves robustness under adversarial conditions, achieving up to 12.9% and 12.2% higher accuracy than state-of-the-art solutions in DMR and TMR configurations, respectively, when attacks are individually crafted for each image. Furthermore, against universal adversarial attacks, our solution achieves even greater accuracy gains, with up to 26.8% and 26.0% higher accuracy in DMR and TMR configurations, respectively.

Martí Caro, Axel Brando, Jaume Abella · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.