<p>With the growing prevalence of deep learning, the risk of adversarial attacks has become increasingly prominent. Among the many key challenges, the efficiency of adversarial sample generation remains an urgent problem, as most traditional attack methods suffer from high computational costs and long generation times. To address this limitation, we propose a novel adversarial attack framework based on a multistage diffusion model-FastMS-CDA. Unlike traditional diffusion attacks that uniformly inject perturbations across the entire denoising trajectory, FastMS-CDA divides the denoising process into multiple sub-stages, allowing perturbations to be injected at each stage. This design not only accelerates the sampling process, but also enhances the success rate of adversarial attacks. Furthermore, we have designed an evaluation metric aimed at dynamically balancing attack success rate and generation time, enabling flexible optimization for specific application needs, making FastMS-CDA both efficient and practical. Extensive experiments conducted on CIFAR-10, MNIST, SVHN, and ImageNet demonstrate the effectiveness of our method. On the MNIST dataset, FastMS-CDA generates each image in just 0.5 milliseconds while maintaining a high attack success rate, outperforming several state-of-the-art baseline methods in both effectiveness and efficiency. </p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

FastMS-CDA: speeding up adversarial sample generation with multistage diffusion model

  • Linying Zhu,
  • Shanshan Wang,
  • Zhenxiang Chen,
  • Yi Zhang

摘要

With the growing prevalence of deep learning, the risk of adversarial attacks has become increasingly prominent. Among the many key challenges, the efficiency of adversarial sample generation remains an urgent problem, as most traditional attack methods suffer from high computational costs and long generation times. To address this limitation, we propose a novel adversarial attack framework based on a multistage diffusion model-FastMS-CDA. Unlike traditional diffusion attacks that uniformly inject perturbations across the entire denoising trajectory, FastMS-CDA divides the denoising process into multiple sub-stages, allowing perturbations to be injected at each stage. This design not only accelerates the sampling process, but also enhances the success rate of adversarial attacks. Furthermore, we have designed an evaluation metric aimed at dynamically balancing attack success rate and generation time, enabling flexible optimization for specific application needs, making FastMS-CDA both efficient and practical. Extensive experiments conducted on CIFAR-10, MNIST, SVHN, and ImageNet demonstrate the effectiveness of our method. On the MNIST dataset, FastMS-CDA generates each image in just 0.5 milliseconds while maintaining a high attack success rate, outperforming several state-of-the-art baseline methods in both effectiveness and efficiency.