Skip to content
Open access

Boosting the Transferability of Adversarial Attacks with Semantic-Invariance and Low-Gradient Replacement

Jul 2026 · Mathematics · 0 citations

Abstract

Deepneural networks are highly vulnerable to adversarial examples, which are generatedby introducing subtle perturbations to input data to mislead model classification. Currently,transfer-based attacks are prevalent in adversarial example generation and canbe categorized into input transformation-based and gradient-based methods. However,most input transformation-based methods tend to produce augmented replicas that aresemantically inconsistent with the original inputs, while gradient-based methods oftenleave low-gradient regions unperturbed within the model’s critical attention areas. Theselimitations constrain further improvements in adversarial transferability. In this work, wepropose a Semantic-Invariance and Low-Gradient Replacement Method (SLRM) to addressthese challenges. Our framework integrates semantically consistent augmentation andgradient replacement as follows: (1) a feature extractor captures semantic features fromoriginal inputs and a reconstructor generates augmented replicas that preserve semanticfidelity to enhance input diversity, and (2) low-gradient regions in adversarial examplesare systematically replaced with corresponding regions from augmented replicas to eliminatethe under-perturbed areas critical for model robustness. Comprehensive empiricalevaluations on ImageNet demonstrate that SLRM significantly enhances the transferabilityof baseline methods and seamlessly integrates with state-of-the-art approaches to furtherimprove their performance. Moreover, SLRM substantially improves the robustness ofbaseline methods against defended models, achieving superior attack success rates underadvanced adversarial defenses.

Read PDF