Ensemble of Intermediate-Level Attacks to Boost Adversarial Transferability
摘要
Adversarial examples are effective at deceiving deep neural network models for which they are specifically crafted and also demonstrate transferability across different models. This characteristic facilitates attacks in black-box scenarios, where the internal workings of the victim models are inaccessible. The Intermediate-Level Attack (ILA) enhances transferability by guiding the direction of the generation of perturbations using intermediate-level outputs. However, ILA struggles with transferring examples between models with different architectures, such as from Convolutional Neural Networks (CNNs) to Vision Transformers (ViTs). To address this, we introduce the Ensemble of Intermediate-Level Attacks (EILA). This approach leverages intermediate outputs from multiple source models to more effectively guide perturbation directions in the generation of adversarial examples. By adopting a shared guidance adversarial example strategy, EILA reduces conflicts in perturbation directions across different models, thereby enhancing overall transfer performance. Experimental results reveal significant enhancements in the transferability of adversarial examples across a range of deep learning models, demonstrating the effectiveness of EILA.