LGV: Boosting Adversarial Example Transferability from Large Geometric Vicinity

07/26/2022
by   Martin Gubri, et al.
0

We propose transferability from Large Geometric Vicinity (LGV), a new technique to increase the transferability of black-box adversarial attacks. LGV starts from a pretrained surrogate model and collects multiple weight sets from a few additional training epochs with a constant and high learning rate. LGV exploits two geometric properties that we relate to transferability. First, models that belong to a wider weight optimum are better surrogates. Second, we identify a subspace able to generate an effective surrogate ensemble among this wider optimum. Through extensive experiments, we show that LGV alone outperforms all (combinations of) four established test-time transformations by 1.8 to 59.9 percentage points. Our findings shed new light on the importance of the geometry of the weight space to explain the transferability of adversarial examples.

READ FULL TEXT

page 10

page 30

page 31

page 32

page 33

research
06/16/2022

Boosting the Adversarial Transferability of Surrogate Model with Dark Knowledge

Deep neural networks (DNNs) for image classification are known to be vul...
research
04/05/2023

Going Further: Flatness at the Rescue of Early Stopping for Adversarial Example Transferability

Transferability is the property of adversarial examples to be misclassif...
research
03/16/2023

Rethinking Model Ensemble in Transfer-based Adversarial Attacks

Deep learning models are vulnerable to adversarial examples. Transfer-ba...
research
08/13/2022

MaskBlock: Transferable Adversarial Examples with Bayes Approach

The transferability of adversarial examples (AEs) across diverse models ...
research
03/17/2023

Fuzziness-tuned: Improving the Transferability of Adversarial Examples

With the development of adversarial attacks, adversairal examples have b...
research
07/15/2023

Why Does Little Robustness Help? Understanding Adversarial Transferability From Surrogate Training

Adversarial examples (AEs) for DNNs have been shown to be transferable: ...

Please sign up or login with your details

Forgot password? Click here to reset