Skip to content

Improving Adversarial Transferability with Local Perturbation Augmentation

· 0 citations · 53 references

TL;DR

This paper reveals that the iterative optimization process tends to over-specialize adversarial perturbations to the local gradient characteristics of the surrogate model, thereby hindering their transferability to other models, and proposes a novel attack method called Local Perturbation Augmentation Attack.

View source

Similar papers

Preprint Aug 2026

Learning with Bilevel-Minimax Optimization for Efficient and Reliable Transfer Attacks

This work proposes BMAT (Bilevel-Minimax Adversarial Transfer), an integrated bottom-up solver that combines a Soft Weight Modulator and an Implicit Gradient Approximator to enable ternary coupling among initialization, surrogate adaptation, and perturbation optimization.

Yaohua Liu, Yi-Fan Guo, Jia-Xin Gao · 0 citations
#machine learning Preprint Sep 2026

Robust Policy Optimization via Adversarial Importance Sampling

This work introduces Adversarial Importance Sampling (Advis), a method that uses importance sampling over trajectories from standard training to estimate and optimize verifiable worst-case returns and introduces advrl, a modular PyTorch library that provides clean, single-file implementations of existing robustness met...

Amine Andam, Jamal Bentahar, M. Hedabou · 0 citations
Sep 2026

Toward Improving Stochastic Neural Network Robustness via Arbitrary Distribution Injection.

Adversarial attacks pose significant challenges to the security and robustness of deep-learning models. Stochastic neural networks (SNNs) have shown promising effectiveness in improving robustness by injecting stochastic noise into model activations, features, or weights. However, most existing SNN-based defenses rely...

Rui Zhou, Hao Yang, Wen-Xu Wang et al. · 0 citations
Sep 2026

Boosting cross-architecture adversarial transferability by enhanced deformation attack.

The Enhanced Deformation Attack (EDA), which estimates attack gradients over stochastically transformed views of the current adversarial image, achieves the highest mean attack success rate (ASR) on ViT targets for all four CNN sources, outperforming the strongest source-specific baseline.

Jia-Cheng Wang, Hegui Zhu, Yi-Fan Zhang et al. · 0 citations
Jul 2026

Adversarially Robust Self-Distillation

To mitigate the vulnerability of deep neural networks in the face of adversarial attacks, a variety of defense strategies have been proposed in recent years. Adversarially robust distillation provides an effective approach by transferring knowledge from a robust teacher model to a student model. However, most existing...

Rihao Li, Ran Wang, Meng Hu · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.