Improving the Transferability of Adversarial Examples with Advanced Diversity-Ensemble Method

Yinhu Xu,Qi Chu,Nenghai Yu
DOI: https://doi.org/10.1109/DSC53577.2021.00037
2021-01-01
Abstract:Recent trend on transferable adversarial attacks focuses on applying different transformations on input images to improve input diversity. DEM, the recently proposed state-of-the-art method, adopts a diversity-ensemble method that contains multiple resize-padding-resize transformation branches to improve transferability. Despite its impressive attacking performance, we observe that the input diversity of DEM is still limited. In light of this, we propose an Advanced Diversity-Ensemble Method (ADEM) to further improve the transferability of adversarial examples. Specifically, we enlarge the range of image proportion and eliminate the overlap between different diversity scales existing in DEM to further improve the input diversity. Extensive experiments demonstrate the effectiveness of the proposed method.
What problem does this paper attempt to address?