Skip to content
Open access

Boosting the Transferability of Adversarial Attacks with Semantic-Invariance and Low-Gradient Replacement

Jul 2026 · Mathematics · Vol 14, pp. 2392 · 0 citations

Abstract

Deepneural networks are highly vulnerable to adversarial examples, which are generatedby introducing subtle perturbations to input data to mislead model classification. Currently,transfer-based attacks are prevalent in adversarial example generation and canbe categorized into input transformation-based and gradient-based methods. However,most input transformation-based methods tend to produce augmented replicas that aresemantically inconsistent with the original inputs, while gradient-based methods oftenleave low-gradient regions unperturbed within the model’s critical attention areas. Theselimitations constrain further improvements in adversarial transferability. In this work, wepropose a Semantic-Invariance and Low-Gradient Replacement Method (SLRM) to addressthese challenges. Our framework integrates semantically consistent augmentation andgradient replacement as follows: (1) a feature extractor captures semantic features fromoriginal inputs and a reconstructor generates augmented replicas that preserve semanticfidelity to enhance input diversity, and (2) low-gradient regions in adversarial examplesare systematically replaced with corresponding regions from augmented replicas to eliminatethe under-perturbed areas critical for model robustness. Comprehensive empiricalevaluations on ImageNet demonstrate that SLRM significantly enhances the transferabilityof baseline methods and seamlessly integrates with state-of-the-art approaches to furtherimprove their performance. Moreover, SLRM substantially improves the robustness ofbaseline methods against defended models, achieving superior attack success rates underadvanced adversarial defenses.

Read PDF

Similar papers

Open access Aug 2026

Perspective-Invariant Attack With Enhanced Transferability of Adversarial Examples

This work proposes a Perspective-Invariant Attack (PIA), which introduces a multi-DOF vertex sampling strategy that systematically covers the perspective transformation hierarchy from 2-DOF translation to 8-DOF projective mapping, and proposes PIA-Mix, a generic extension that maintains a complementary transformation pool and efficiently combines the authors' perspective transformation with auxiliary methods for improved transferability.

Kaisheng Liang, Yiming Cao, Bin Xiao · 0 citations
Open access Aug 2026

Adversarial Purification by Consistency-aware Latent Space Optimization on Data Manifolds.

This paper reveals that samples generated by a well-trained generative model are close to clean ones but far from adversarial ones, and proposes Consistency Model-based Adversarial Purification (CMAP), which optimizes vectors within the latent space of a pre-trained consistency model to generate samples for restoring clean data.

Shuhai Zhang, Jiahao Yang, Hui Luo et al. · 0 citations

Understanding and Exploiting Phase Sensitivity for Attacking Large Vision–Language Models

This paper proposes a novel LVLM attack method, called BadPhase with further backdoor designs, to implant adversarial phase as triggers into any image inputs via data poisoning so as to control the LVLMs’ predictions and finds that LVLMs are sensitive to the phase-aware image structure.

Daizong Liu, Junhao Dong, Xiang Fang et al. · 0 citations
Preprint Aug 2026

IDATA: Scalable Invertible Diffusion for Unrestricted Adversarial Transfer Attack

Extensive experiments demonstrate that IDATA consistently outperforms state-of-the-art baselines in attack success rate, memory efficiency, and visual imperceptibility, suggesting that IDATA is a promising tool for black-box robustness evaluation of deep visual models.

Yi Pan, Jun-Jie Huang, Tianrui Liu et al. · 0 citations
Jul 2026

Learning from Adversity: Semantic-Aware Mask Refinement through Adversarial Perturbation

Phoenix is introduced, a novel framework that leverages adversarial learning to generate semantically meaningful noise patterns and contrastive learning to model refinement relationships that significantly outperforms existing methods across diverse tasks, while consistently enhancing state-of-the-art segmentation models with substantial improvements.

Beomyoung Kim, S. Hwang · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.