JOURNAL ARTICLE

Boosting Adversarial Transferability With Learnable Patch-Wise Masks

Xingxing WeiShiji Zhao

Year: 2023 Journal:   IEEE Transactions on Multimedia Vol: 26 Pages: 3778-3787   Publisher: Institute of Electrical and Electronics Engineers

Abstract

Adversarial examples have attracted widespread attention in security-critical applications because of their transferability across different models. Although many methods have been proposed to boost adversarial transferability, a gap still exists between capabilities and practical demand. In this article, we argue that the model-specific discriminative regions are a key factor causing overfitting to the source model, and thus reducing the transferability to the target model. For that, a patch-wise mask is utilized to prune the model-specific regions when calculating adversarial perturbations. To accurately localize these regions, we present a learnable approach to automatically optimize the mask. Specifically, we simulate the target models in our framework, and adjust the patch-wise mask according to the feedback of the simulated models. To improve the efficiency, the differential evolutionary (DE) algorithm is utilized to search for patch-wise masks for a specific image. During iterative attacks, the learned masks are applied to the image to drop out the patches related to model-specific regions, thus making the gradients more generic and improving the adversarial transferability. The proposed approach is a preprocessing method and can be integrated with existing methods to further boost the transferability. Extensive experiments on the ImageNet dataset demonstrate the effectiveness of our method. We incorporate the proposed approach with existing methods to perform ensemble attacks and achieve an average success rate of 93.01% against seven advanced defense methods, which can effectively enhance the state-of-the-art transfer-based attack performance.

Keywords:
Adversarial system Computer science Boosting (machine learning) Transferability Artificial intelligence Pattern recognition (psychology) Machine learning

Metrics

14
Cited By
3.58
FWCI (Field Weighted Citation Impact)
50
Refs
0.92
Citation Normalized Percentile
Is in top 1%
Is in top 10%

Citation History

Topics

Adversarial Robustness in Machine Learning
Physical Sciences →  Computer Science →  Artificial Intelligence
Generative Adversarial Networks and Image Synthesis
Physical Sciences →  Computer Science →  Computer Vision and Pattern Recognition
Advanced Image Processing Techniques
Physical Sciences →  Computer Science →  Computer Vision and Pattern Recognition

Related Documents

JOURNAL ARTICLE

Boosting Adversarial Training with Learnable Distribution

Kai ChenJinwei WangJames Msughter AdekeGuangjie LiuYuewei Dai

Journal:   Computers, materials & continua/Computers, materials & continua (Print) Year: 2024 Vol: 78 (3)Pages: 3247-3265
JOURNAL ARTICLE

Boosting Fast Adversarial Training With Learnable Adversarial Initialization

Xiaojun JiaYong ZhangBaoyuan WuJue WangXiaochun Cao

Journal:   IEEE Transactions on Image Processing Year: 2022 Vol: 31 Pages: 4417-4430
JOURNAL ARTICLE

Boosting Adversarial Transferability Through Adversarial Attack Enhancer

Wenli ZengHong HuangJixin Chen

Journal:   Applied Sciences Year: 2025 Vol: 15 (18)Pages: 10242-10242
© 2026 ScienceGate Book Chapters — All rights reserved.