摘要
Transfer-based black-box attacks are crucial for assessing security vulnerabilities in deep learning models. Input transformation has emerged as an effective approach for enhancing adversarial transferability. However, existing methods tend to emphasize random transformations, or over-rely on attention patterns that are tightly coupled to the surrogate model, thereby limiting the transferability of generated adversarial examples. Therefore, we propose an Attention-Guided Regional Composition (AGRC) attack that enhances adversarial transferability through attention-guided regional composition. Specifically, AGRC first utilizes Grad-CAM to identify decision-critical regions. It then performs weighted-centroid-guided multi-region composition for diverse data augmentation, thereby mitigating excessive reliance on surrogate-specific attention distributions. Furthermore, to enhance the quality of augmented samples, an adaptive smoothing strategy is applied to the input to suppress high-frequency texture components in its salient regions during the process of data augmentation. The gradients aggregated from multiple augmented samples across different scales are used to craft highly transferable adversarial perturbations. Extensive experiments on ImageNet demonstrate that AGRC outperforms the considered baselines, with particularly notable improvements against adversarially trained models.
| 源语言 | 英语 |
|---|---|
| 期刊论文编号 | 134699 |
| 期刊 | Neurocomputing |
| 卷 | 703 |
| DOI | |
| 出版状态 | 已出版 - 28 11月 2026 |
学术指纹
探究 'Enhancing adversarial transferability via attention-guided multi-region composition and adaptive smoothing' 的科研主题。它们共同构成独一无二的学术指纹。引用此
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver