论文

ST:用原始-对偶正则化提升可迁移对抗攻击的隐蔽性

Pareto-Improving Adversarial Attacks with Primal-Dual Regularization

精选理由

arXiv 上这篇论文提出 ST 攻击包装器,不换模型就能让对抗攻击更隐蔽,LPIPS 提升 17% 还不掉成功率,做对抗鲁棒性研究的可以看看。

论文提出名为 ST 的隐蔽迁移攻击方法,作为即插即用的原始-对偶包装器,在标准约束目标上加入 L∞ 饱和正则器,通过投影原始步与 L1 球投影的对偶变量两步更新求解,无需辅助模型或手工感知先验。作者指出迁移性与隐蔽性的冲突源于固定 ε 预算的评估方式,在 ASR-隐蔽性 Pareto 前沿上并不成立。实验显示,在 ε=16/255 下,ST 相对各基础攻击在 LPIPS 上平均提升 17%,NIQE 上提升 14%,同时攻击成功率保持或提高。在高 ASR 水平下,最强的 ST 变体还能 Pareto 优于专门面向隐蔽性的迁移攻击。代码将发布在 GitHub 的 AndssY/ST 仓库。

原文 · arXiv cs.LG

Pareto-Improving Adversarial Attacks with Primal-Dual Regularization

Transferable adversarial attacks are arguably the most practical black-box threat model. Under the same perturbation budget, stronger transfer attacks attain higher attack success rate (ASR), yet their imperceptibility also tends to degrade. Under such a fixed-budget protocol, transferability and imperceptibility therefore appear to trade off against each other. We argue that this conflict is an artifact of fixed-budget evaluation, not an intrinsic trade-off. When attacks are compared on the ASR--imperceptibility Pareto frontier obtained by sweeping $ε$, stronger transfer attacks already attain better imperceptibility at matched ASR than weaker ones. To exploit this latent advantage, we introduce the stealthy transfer attack ST, a plug-in primal-dual wrapper that adds an $L_\infty$ saturation regularizer to the standard constrained objective and resolves it through a two-step primal-dual update: a projected primal step on the perturbation coupled with an $L_1$-ball projection on a dual variable that absorbs the regularizer through Fenchel duality, requiring no auxiliary models or handcrafted perceptual priors. Empirically, ST extends the Pareto frontier across different base attacks and additional surrogate architectures. At $ε{=}16/255$, average imperceptibility gains over each base attack are $17\%$ on LPIPS and $14\%$ on NIQE while ASR is preserved or improved. At matched high-ASR levels, the strongest ST variants further Pareto-dominate dedicated stealth-oriented transfer attacks, confirming that the latent imperceptibility advantage of strong transfer attacks can be unlocked by a primal-dual optimization wrapper without sacrificing transferability. Code will be made available at \url{https://github.com/AndssY/ST}.