TY - JOUR
T1 - HORNET
T2 - Fast and minimal adversarial perturbations
AU - Wu, Jiaping
AU - Emanuele Cinà, Antonio
AU - Villani, Francesco
AU - Xia, Zhaoqiang
AU - Demetrio, Luca
AU - Oneto, Luca
AU - Anguita, Davide
AU - Roli, Fabio
AU - Feng, Xiaoyi
N1 - Publisher Copyright:
© 2026 The Authors
PY - 2026/4/15
Y1 - 2026/4/15
N2 - Fixed-budget attacks aim to generate adversarial examples—carefully crafted inputs designed to induce misclassifications during inference—while adhering to a predefined perturbation budget. These attacks maximize misclassification confidence and benefit from the transferability property, enabling the generated adversarial examples to remain effective even against multiple unknown models. However, to preserve their transferability, such attacks often yield perceptible perturbations, compromising the visual integrity of the adversarial examples. In this paper, we introduce HORNET, an extension of gradient-based fixed-budget attacks designed to minimize the perturbation magnitude of adversarial examples while maintaining their transferability against the target model. HORNET utilizes a distinct source model to craft the adversarial examples and employs a limited number of queries to the unknown target model to further minimize perturbation magnitude. We evaluate HORNET empirically by integrating it with 41 existing attack implementations and testing it against 9 different models, resulting in a total of 1700 unique configurations. Our results demonstrate that HORNET outperforms the state of the art in generating minimally perturbed yet highly transferable adversarial examples across all tested models. Code available at: https://github.com/louiswup/HORNET.
AB - Fixed-budget attacks aim to generate adversarial examples—carefully crafted inputs designed to induce misclassifications during inference—while adhering to a predefined perturbation budget. These attacks maximize misclassification confidence and benefit from the transferability property, enabling the generated adversarial examples to remain effective even against multiple unknown models. However, to preserve their transferability, such attacks often yield perceptible perturbations, compromising the visual integrity of the adversarial examples. In this paper, we introduce HORNET, an extension of gradient-based fixed-budget attacks designed to minimize the perturbation magnitude of adversarial examples while maintaining their transferability against the target model. HORNET utilizes a distinct source model to craft the adversarial examples and employs a limited number of queries to the unknown target model to further minimize perturbation magnitude. We evaluate HORNET empirically by integrating it with 41 existing attack implementations and testing it against 9 different models, resulting in a total of 1700 unique configurations. Our results demonstrate that HORNET outperforms the state of the art in generating minimally perturbed yet highly transferable adversarial examples across all tested models. Code available at: https://github.com/louiswup/HORNET.
KW - Adversarial examples
KW - Adversarial perturbation
KW - Deep neural networks
KW - Machine learning
KW - Machine learning security
KW - Transferability
UR - https://www.scopus.com/pages/publications/105027434169
U2 - 10.1016/j.ins.2025.123028
DO - 10.1016/j.ins.2025.123028
M3 - 文章
AN - SCOPUS:105027434169
SN - 0020-0255
VL - 735
JO - Information Sciences
JF - Information Sciences
M1 - 123028
ER -