Skip to main navigation Skip to search Skip to main content

HORNET: Fast and minimal adversarial perturbations

  • Jiaping Wu
  • , Antonio Emanuele Cinà
  • , Francesco Villani
  • , Zhaoqiang Xia
  • , Luca Demetrio
  • , Luca Oneto
  • , Davide Anguita
  • , Fabio Roli
  • , Xiaoyi Feng
  • Northwestern Polytechnical University Xian
  • University of Genoa

Research output: Contribution to journalArticlepeer-review

Abstract

Fixed-budget attacks aim to generate adversarial examples—carefully crafted inputs designed to induce misclassifications during inference—while adhering to a predefined perturbation budget. These attacks maximize misclassification confidence and benefit from the transferability property, enabling the generated adversarial examples to remain effective even against multiple unknown models. However, to preserve their transferability, such attacks often yield perceptible perturbations, compromising the visual integrity of the adversarial examples. In this paper, we introduce HORNET, an extension of gradient-based fixed-budget attacks designed to minimize the perturbation magnitude of adversarial examples while maintaining their transferability against the target model. HORNET utilizes a distinct source model to craft the adversarial examples and employs a limited number of queries to the unknown target model to further minimize perturbation magnitude. We evaluate HORNET empirically by integrating it with 41 existing attack implementations and testing it against 9 different models, resulting in a total of 1700 unique configurations. Our results demonstrate that HORNET outperforms the state of the art in generating minimally perturbed yet highly transferable adversarial examples across all tested models. Code available at: https://github.com/louiswup/HORNET.

Original languageEnglish
Article number123028
JournalInformation Sciences
Volume735
DOIs
StatePublished - 15 Apr 2026

Keywords

  • Adversarial examples
  • Adversarial perturbation
  • Deep neural networks
  • Machine learning
  • Machine learning security
  • Transferability

Fingerprint

Dive into the research topics of 'HORNET: Fast and minimal adversarial perturbations'. Together they form a unique fingerprint.

Cite this