Jie Li 0086

dblp:17/2703-86 · DBLP profile ↗
← Back
2ranked-venue papers
0as first author
2since 2021 · last 2024
0009-0004-9787-0527ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 2 since 2021
YearPublicationVenuePosition
2024 UCG: A Universal Cross-Domain Generator for Transferable Adversarial Examples
abstract
Generating transferable adversarial examples is a challenging issue in adversarial example attacks. Existing works on transferable adversarial examples generation mainly focus on models with similar architectures and trained on the same data domain. However, in practice, information such as the model architecture type and training data domain is unlikely to be revealed in deployed models. In this work, we introduce the Universal Cross-domain Generator (UCG), a pioneering framework for transferable adversarial examples that is the first to simultaneously address both cross-domain and cross-architecture challenges in adversarial attacks. The design of UCG is mainly inspired by two key observations. First, there exists some commonality in attention regions even when the structures of models are different. Second, there exists prevalent instability of intermediate-feature maps across cross-domain models. We accordingly design anattention transfermechanism and aroughness abatementmechanism to enhance the cross-architecture and cross-domain transferability of the generated adversarial examples. Moreover, we propose anintegrated transformation processingtechnique to improve the transferability of the generated adversarial examples under different transformations. Experimental results demonstrate that, compared with state-of- the-art solutions, UCG improves the average transferable attack success rate by 15.3%, 7.9%, and 8.2% in the cross-architecture task (convolutional neural networks (CNNs) to vision transformers (ViTs)), coarse-grained cross-domain tasks, and fine-grained cross-domain tasks, respectively.
Zhankai Li, Weiping Wang 0003, Jie Li 0086, Kai Chen 0012, Shigeng Zhang
IEEE Trans. Inf. Forensics Secur.3
2024 Foolmix: Strengthen the Transferability of Adversarial Examples by Dual-Blending and Direction Update Strategy
abstract
Adversarial example attacks are deemed to be a serious threat to deep neural network (DNN) models. Generating adversarial examples in white-box settings has been well-studied, however, it remains challenging to generate transferable adversarial examples that successfully attack black-box models. This work proposes Foolmix, a novel method for generating transferable adversarial examples for black-box attacks. The design of Foolmix is inspired by our observation that adversarial examples with high transferability usually carry multi-class features in the latent space of DNN models. Thus, we propose a dual-blending strategy that blends the image with a set of random pixel-blocks and blends the gradient by calculating the loss of the blended image for both the ground-truth label and a set of random labels. The dual-blending strategy pressures the example to penetrate multiple class regions and gain multi-class features in the latent space, greatly enhancing the transferability of the generated adversarial example. However, the randomness in the blending process might also pressure the example to approach the boundary of the original class region, which lowers the robustness of the example. To mitigate this problem, we further propose an update method in the starting forward direction to guide the generated adversarial example to go deep into multi-class adversarial regions while being globally far away from the original class region. Compared to state-of-the-art transformation-based attacks, Foolmix significantly enhances the transferability of generated adversarial examples, boosting the average transferable attack success rate by 13.2% and 16.9% on mainstream CNNs and ViTs respectively, while achieving better defense breakthrough ability.
Zhankai Li, Weiping Wang 0003, Jie Li 0086, Kai Chen 0012, Shigeng Zhang
IEEE Trans. Inf. Forensics Secur.3