JOURNAL ARTICLE

Improving Adversarial Transferability with Heuristic Random Transformation

Abstract

Deep neural network is very vulnerable to adversarial examples, which add subtle perturbations on the original image that are difficult for human to perceive, but can make network produce wrong classification results. The current advanced adversarial attack methods can achieve satisfactory results under the white-box setting, but when attacking the black-box model, especially for the defense models, they show poor transferability. It can mainly improve the transferability of adversarial attacks under black-box settings from two perspectives of gradient optimization and image transformation. We propose a new image transformation method, which is different from treating each pixel equally in previous works. We consider using the size of gradient value to reflect the importance of pixels, assigning different scaling factors to each gradient unit, and conducting heuristic random transformation on the images input in each iteration to achieve data enhancement, obtain more stable update direction and escape from local optimal values. Extensive experiments on ImageNet Dataset show that the proposed method has better performance than the existing methods. In addition, our method can also be combined with other attack methods to further improve the transferability of adversarial attacks. Besides, our approach also has excellent performance on the defense models.

Keywords:
Transferability Adversarial system Computer science Transformation (genetics) Heuristic Artificial intelligence Black box Image (mathematics) Pixel Artificial neural network Machine learning Deep learning Deep neural networks Pattern recognition (psychology) Data mining

Metrics

1
Cited By
0.26
FWCI (Field Weighted Citation Impact)
0
Refs
0.54
Citation Normalized Percentile
Is in top 1%
Is in top 10%

Citation History

Topics

Adversarial Robustness in Machine Learning
Physical Sciences →  Computer Science →  Artificial Intelligence
Advanced Neural Network Applications
Physical Sciences →  Computer Science →  Computer Vision and Pattern Recognition
COVID-19 diagnosis using AI
Health Sciences →  Medicine →  Radiology, Nuclear Medicine and Imaging

Related Documents

JOURNAL ARTICLE

Improving the Adversarial Transferability via Histogram Transformation

Xianling LuWan ChenLifeng Huang

Journal:   IEEE Signal Processing Letters Year: 2025 Vol: 32 Pages: 3949-3953
JOURNAL ARTICLE

Improving the Transferability of Adversarial Examples with Image Affine Transformation

Heng YinHengwei ZhangZheming LiZhilin Liu

Journal:   Journal of Physics Conference Series Year: 2021 Vol: 1955 (1)Pages: 012052-012052
BOOK-CHAPTER

Improving Transferability of Adversarial Examples by SVD Transformation

Xiaoyu LiJ. MaiChong-zhi Gao

Communications in computer and information science Year: 2025 Pages: 262-275
JOURNAL ARTICLE

FDT: Improving the transferability of adversarial examples with frequency domain transformation

Jie LingJinhui ChenHonglei Li

Journal:   Computers & Security Year: 2024 Vol: 144 Pages: 103942-103942
JOURNAL ARTICLE

Improving transferability of adversarial examples with powerful affine-shear transformation attack

X. WangChunguang HuangHai Cheng

Journal:   Computer Standards & Interfaces Year: 2022 Vol: 84 Pages: 103693-103693
© 2026 ScienceGate Book Chapters — All rights reserved.