A High-Transferability Adversarial Sample Generation Method Incorporating Frequency Domain Transformations

Sijian Yan,Zhengjie Deng,Jiale Dong,Xiyan Li
DOI: https://doi.org/10.3390/electronics13224480
IF: 2.9
2024-11-20
Electronics
Abstract:Adversarial attack methods have achieved satisfactory results in white-box attack scenarios, but their performance declines when transferred to other deep neural network (DNN) models. Currently, there are many methods to improve the transferability of adversarial samples, and enhancing transferability through input transformations is an effective approach. However, most existing input transformations are performed in the spatial domain, neglecting transformations in the frequency domain. Therefore, this paper proposes a novel input transformation-based attack: the frequency domain enhancement (FDE) method, which performs input transformations in the frequency domain to increase input diversity. Specifically, this method processes input images in the frequency domain, suppresses high-frequency information in the input images, and then randomly amplifies certain frequency domain information, generating adversarial samples with stronger transferability. Experimental results show that adversarial samples generated through FDE demonstrate significant improvement in transferability on both undefended and defended models on the ImageNet dataset. Notably, this method can be combined with many existing techniques to further enhance the transferability of adversarial samples.
engineering, electrical & electronic,computer science, information systems,physics, applied
What problem does this paper attempt to address?