Aug 2026· Neural Networks· Vol 205 Pt B, pp.
109487
· 0 citations· 42 references
Medicine
TL;DR
This approach improves transferability by combining different parameter initializations to generate a diversified set of surrogate models and integrates an adversarial makeup technique that generates adversarial disguises from reference images, thereby further boosting the attack's effectiveness.
Abstract
Facial recognition (FR) models are vulnerable to adversarial attacks, in which attackers manipulate facial images to expose system vulnerabilities, underscoring the urgent need to improve the transferability of adversarial attacks. However, existing methods fail to fully leverage diverse initialization strategies for extending surrogate models, thereby limiting the transferability of adversarial samples. To address this, we propose the Multi-Initialization Enhanced Aggregation (MEA) attack method. This approach improves transferability by combining different parameter initializations to generate a diversified set of surrogate models. MEA consists of two stages: Multi-Initialization Adversarial Enhancement (MIAE) and Enhanced Adversarial Aggregation (EAA). In the MIAE stage, we enhance model diversity through checkpoint saving driven by diversity metrics and multi-layer initialization. In the EAA stage, we further enhance transferability by adding perturbations to high-level features. Additionally, we integrate an adversarial makeup technique that generates adversarial disguises from reference images, thereby further boosting the attack's effectiveness. Experimental results show that MEA outperforms the second-best input transformation attack by 20.35% and achieves a 9.22% improvement over existing facial adversarial attacks.
This work proposes a Perspective-Invariant Attack (PIA), which introduces a multi-DOF vertex sampling strategy that systematically covers the perspective transformation hierarchy from 2-DOF translation to 8-DOF projective mapping, and proposes PIA-Mix, a generic extension that maintains a complementary transformation pool and efficiently combines the authors' perspective transformation with auxiliary methods for improved transferability.
Kaisheng Liang, Yiming Cao, Bin Xiao· IEEE Transactions on Informa...· 0 citations
Optimize Deep Learning–based Adversarial Defense Mechanism (ODL-ADM) is proposed in this work, which projects adversarial samples into an immune feature space that is both discriminative and resistant to perturbations.
Sheilla Ann Bangoy Pacheco, Mahesh Goyani, Jayzel P. Bangoy et al.· ITEGAM- Journal of Engineeri...· 0 citations
The proposed DiffAttack framework significantly outperforms existing adversarial techniques, achieving a high average attack success rate of 84.86% across multiple face recognition models (e.g., FaceNet).
Omid Ahmadieh, Nima Karimian· arXiv.org· 0 citations
A Color Adversarial Patch generation algorithm that leverages style transfer principles to produce visually natural color patches while maintaining high attack success rates, demonstrating the feasibility of concealed physical-domain attacks on palmprint recognition systems.
Yue Liu, Qi Xiong, Lu Leng et al.· Electronics· 0 citations
FDT-PC (Frequency Domain Transformation with Perceptual Constraints), a novel method that enhances adversarial transferability across different model architectures, is proposed, which achieves superior black-box attack performance on both CNNs and Vision Transformers, outperforming existing state-of-the-art input transformation methods.
Bo Li, Li Tang, Xin Jin et al.· ACM Transactions on Multimed...· 0 citations
A method to analyze ANNs designed for image classification from an adversarial robustness perspective and implemented an ablation and fine-tuning strategy that successfully boosted the robustness of the ANNs against a variant of the Auto-PGD attack under different threat models.