Jul 2026· Mathematics· Vol 14, pp. 2392· 0 citations
Abstract
Deepneural networks are highly vulnerable to adversarial examples, which are generatedby introducing subtle perturbations to input data to mislead model classification. Currently,transfer-based attacks are prevalent in adversarial example generation and canbe categorized into input transformation-based and gradient-based methods. However,most input transformation-based methods tend to produce augmented replicas that aresemantically inconsistent with the original inputs, while gradient-based methods oftenleave low-gradient regions unperturbed within the model’s critical attention areas. Theselimitations constrain further improvements in adversarial transferability. In this work, wepropose a Semantic-Invariance and Low-Gradient Replacement Method (SLRM) to addressthese challenges. Our framework integrates semantically consistent augmentation andgradient replacement as follows: (1) a feature extractor captures semantic features fromoriginal inputs and a reconstructor generates augmented replicas that preserve semanticfidelity to enhance input diversity, and (2) low-gradient regions in adversarial examplesare systematically replaced with corresponding regions from augmented replicas to eliminatethe under-perturbed areas critical for model robustness. Comprehensive empiricalevaluations on ImageNet demonstrate that SLRM significantly enhances the transferabilityof baseline methods and seamlessly integrates with state-of-the-art approaches to furtherimprove their performance. Moreover, SLRM substantially improves the robustness ofbaseline methods against defended models, achieving superior attack success rates underadvanced adversarial defenses.
This work proposes a Perspective-Invariant Attack (PIA), which introduces a multi-DOF vertex sampling strategy that systematically covers the perspective transformation hierarchy from 2-DOF translation to 8-DOF projective mapping, and proposes PIA-Mix, a generic extension that maintains a complementary transformation pool and efficiently combines the authors' perspective transformation with auxiliary methods for improved transferability.
Kaisheng Liang, Yiming Cao, Bin Xiao· IEEE Transactions on Informa...· 0 citations
This paper reveals that samples generated by a well-trained generative model are close to clean ones but far from adversarial ones, and proposes Consistency Model-based Adversarial Purification (CMAP), which optimizes vectors within the latent space of a pre-trained consistency model to generate samples for restoring clean data.
Shuhai Zhang, Jiahao Yang, Hui Luo et al.· IEEE Transactions on Pattern...· 0 citations
This paper proposes a novel LVLM attack method, called BadPhase with further backdoor designs, to implant adversarial phase as triggers into any image inputs via data poisoning so as to control the LVLMs’ predictions and finds that LVLMs are sensitive to the phase-aware image structure.
Daizong Liu, Junhao Dong, Xiang Fang et al.· 0 citations
Extensive experiments demonstrate that IDATA consistently outperforms state-of-the-art baselines in attack success rate, memory efficiency, and visual imperceptibility, suggesting that IDATA is a promising tool for black-box robustness evaluation of deep visual models.
Yi Pan, Jun-Jie Huang, Tianrui Liu et al.· 0 citations
Phoenix is introduced, a novel framework that leverages adversarial learning to generate semantically meaningful noise patterns and contrastive learning to model refinement relationships that significantly outperforms existing methods across diverse tasks, while consistently enhancing state-of-the-art segmentation models with substantial improvements.
Empirical support is provided for the utility of structure-aware perturbation refinement in improving black-box adversarial transferability across heterogeneous visual architectures.
Qi-Rui Lu, Liansong Zong, Fu-Ran Liu et al.· Neural Networks· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.