In the study on Adversarial Example Soups, the authors propose a method to enhance transferability in adversarial attacks by averaging multiple batches of fine-tuned adversarial examples. This approach, orthogonal to existing methods, shows improved attack success rates without increasing computational costs. The research covers various types of adversarial example soups and their impact on different models and defense mechanisms.
The experiments conducted demonstrate that the proposed Adversarial Example Soup (AES) attacks outperform baseline methods in terms of attack success rates. The AES approach provides flexibility and adaptability, offering new insights for further exploration in the field of adversarial attacks.
The study also includes an ablation study to analyze the impact of parameters, such as the number of sampled images, on transferability. Visualizations of CAM attention maps show how AES attacks counteract invalid perturbations and focus on positive perturbations for improved transferability.
Further analysis explores the potential for other types of adversarial example soups and their application in speech adversarial attacks. Overall, the research highlights the effectiveness and generality of AES attacks in enhancing transferability in adversarial scenarios.
Para outro idioma
do conteúdo fonte
arxiv.org
Principais Insights Extraídos De
by Bo Yang,Heng... às arxiv.org 02-29-2024
https://arxiv.org/pdf/2402.18370.pdfPerguntas Mais Profundas