• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

通过基于统计归因的攻击提高对抗样本的可转移性。

Improving transferability of adversarial examples via statistical attribution-based attacks.

作者信息

Zhu Hegui, Jia Yanmeng, Yan Yue, Yang Ze

机构信息

College of Sciences, Northeastern University, Shenyang, 110819, China; Foshan Graduate School of Innovation, Northeastern University, Foshan, 528311, China.

College of Sciences, Northeastern University, Shenyang, 110819, China.

出版信息

Neural Netw. 2025 Jul;187:107341. doi: 10.1016/j.neunet.2025.107341. Epub 2025 Mar 10.

DOI:10.1016/j.neunet.2025.107341
PMID:40086136
Abstract

Adversarial attacks are significant in uncovering vulnerabilities and assessing the robustness of deep neural networks (DNNs), offering profound insights into their internal mechanisms. Feature-level attacks, a potent approach, craft adversarial examples by extensively corrupting the intermediate-layer features of the source model during each iteration. However, it often has imprecise metrics to assess the significance of features and may impose constraints on the transferability of adversarial examples. To address these issues, this paper introduces the Statistical Attribution-based Attack (SAA) method, which emphasizes finding feature importance representations and refining optimization objectives, thereby achieving stronger attack performance. To calculate the Comprehensive Gradient for more accurate feature representation, we introduce the Region-wise Feature Disturbance and Gradient Information Aggregation, which can effectively disrupt the model's attention focus areas. Subsequently, a statistical attribution-based approach is employed, leveraging the average feature information across layers to provide a more advantageous optimization objective. Experiments have validated the superiority of this method. Specifically, SAA improves the attack success rate by 9.3% compared with the second-best method. When combined with input transformation methods, it achieves an average success rate of 79.2% against eight leading defense models.

摘要

对抗攻击对于揭示深度神经网络(DNN)的漏洞和评估其鲁棒性具有重要意义,能为深入了解其内部机制提供深刻见解。特征级攻击作为一种有效的方法,在每次迭代过程中通过大量破坏源模型的中间层特征来生成对抗样本。然而,它通常在评估特征重要性方面缺乏精确的指标,并且可能对对抗样本的可迁移性施加限制。为了解决这些问题,本文引入了基于统计归因的攻击(SAA)方法,该方法强调寻找特征重要性表示并优化优化目标,从而实现更强的攻击性能。为了计算更准确的特征表示的综合梯度,我们引入了区域特征扰动和梯度信息聚合,它可以有效地扰乱模型的注意力聚焦区域。随后,采用基于统计归因的方法,利用各层的平均特征信息来提供更具优势的优化目标。实验验证了该方法的优越性。具体而言,与次优方法相比,SAA将攻击成功率提高了9.3%。当与输入变换方法相结合时,针对八个领先的防御模型,其平均成功率达到了79.2%。

相似文献

1
Improving transferability of adversarial examples via statistical attribution-based attacks.通过基于统计归因的攻击提高对抗样本的可转移性。
Neural Netw. 2025 Jul;187:107341. doi: 10.1016/j.neunet.2025.107341. Epub 2025 Mar 10.
2
DEFEAT: Decoupled feature attack across deep neural networks.击败:跨深度神经网络的解耦特征攻击。
Neural Netw. 2022 Dec;156:13-28. doi: 10.1016/j.neunet.2022.09.009. Epub 2022 Sep 20.
3
Auto encoder-based defense mechanism against popular adversarial attacks in deep learning.基于自动编码器的深度学习中流行对抗攻击防御机制。
PLoS One. 2024 Oct 21;19(10):e0307363. doi: 10.1371/journal.pone.0307363. eCollection 2024.
4
Boosting the transferability of adversarial examples via stochastic serial attack.通过随机串行攻击提升对抗样本的可转移性。
Neural Netw. 2022 Jun;150:58-67. doi: 10.1016/j.neunet.2022.02.025. Epub 2022 Mar 7.
5
Enhancing robustness in video recognition models: Sparse adversarial attacks and beyond.增强视频识别模型的鲁棒性:稀疏对抗攻击及其他。
Neural Netw. 2024 Mar;171:127-143. doi: 10.1016/j.neunet.2023.11.056. Epub 2023 Nov 25.
6
Remix: Towards the transferability of adversarial examples.对抗样本的可迁移性研究
Neural Netw. 2023 Jun;163:367-378. doi: 10.1016/j.neunet.2023.04.012. Epub 2023 Apr 18.
7
Strengthening transferability of adversarial examples by adaptive inertia and amplitude spectrum dropout.通过自适应惯性和幅度谱丢弃增强对抗样本的可转移性。
Neural Netw. 2023 Aug;165:925-937. doi: 10.1016/j.neunet.2023.06.031. Epub 2023 Jun 30.
8
Improving the Transferability of Adversarial Examples by Feature Augmentation.通过特征增强提高对抗样本的可迁移性
IEEE Trans Neural Netw Learn Syst. 2025 May 8;PP. doi: 10.1109/TNNLS.2025.3563855.
9
Transferability of features for neural networks links to adversarial attacks and defences.神经网络特征的可转移性与对抗攻击和防御有关。
PLoS One. 2022 Apr 27;17(4):e0266060. doi: 10.1371/journal.pone.0266060. eCollection 2022.
10
FDAA: A feature distribution-aware transferable adversarial attack method.
Neural Netw. 2024 Oct;178:106467. doi: 10.1016/j.neunet.2024.106467. Epub 2024 Jun 14.