Pith. sign in

REVIEW 1 cited by

Frequency Domain Model Augmentation for Adversarial Attack

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2207.05382 v1 pith:KQGVHQL6 submitted 2022-07-12 cs.CV

classification cs.CV
keywords modelsmodeldomainadversarialattackaugmentationdiversefrequency
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

For black-box attacks, the gap between the substitute model and the victim model is usually large, which manifests as a weak attack performance. Motivated by the observation that the transferability of adversarial examples can be improved by attacking diverse models simultaneously, model augmentation methods which simulate different models by using transformed images are proposed. However, existing transformations for spatial domain do not translate to significantly diverse augmented models. To tackle this issue, we propose a novel spectrum simulation attack to craft more transferable adversarial examples against both normally trained and defense models. Specifically, we apply a spectrum transformation to the input and thus perform the model augmentation in the frequency domain. We theoretically prove that the transformation derived from frequency domain leads to a diverse spectrum saliency map, an indicator we proposed to reflect the diversity of substitute models. Notably, our method can be generally combined with existing attacks. Extensive experiments on the ImageNet dataset demonstrate the effectiveness of our method, \textit{e.g.}, attacking nine state-of-the-art defense models with an average success rate of \textbf{95.4\%}. Our code is available in \url{https://github.com/yuyang-long/SSA}.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Improving the Transferability of 3D Point Cloud Attack via Spectral-aware Admix and Optimization Designs

    cs.CV 2024-12 conditional novelty 5.0 of 10

    SAAO improves transferability of 3D point cloud adversarial attacks by performing Admix-style mixing in the graph Fourier domain with learnable weights and gradient-based path selection, yielding higher transfer attac...

Pith tools