English

Boosting Transferability of Targeted Adversarial Examples via Hierarchical Generative Networks

Machine Learning 2022-07-25 v2 Artificial Intelligence

Abstract

Transfer-based adversarial attacks can evaluate model robustness in the black-box setting. Several methods have demonstrated impressive untargeted transferability, however, it is still challenging to efficiently produce targeted transferability. To this end, we develop a simple yet effective framework to craft targeted transfer-based adversarial examples, applying a hierarchical generative network. In particular, we contribute to amortized designs that well adapt to multi-class targeted attacks. Extensive experiments on ImageNet show that our method improves the success rates of targeted black-box attacks by a significant margin over the existing methods -- it reaches an average success rate of 29.1\% against six diverse models based only on one substitute white-box model, which significantly outperforms the state-of-the-art gradient-based attack methods. Moreover, the proposed method is also more efficient beyond an order of magnitude than gradient-based methods.

Keywords

Cite

@article{arxiv.2107.01809,
  title  = {Boosting Transferability of Targeted Adversarial Examples via Hierarchical Generative Networks},
  author = {Xiao Yang and Yinpeng Dong and Tianyu Pang and Hang Su and Jun Zhu},
  journal= {arXiv preprint arXiv:2107.01809},
  year   = {2022}
}
R2 v1 2026-06-24T03:53:14.753Z