首页|期刊导航|西安电子科技大学学报(自然科学版)|基于ViT的高迁移性黑盒对抗样本生成

基于ViT的高迁移性黑盒对抗样本生成OA

High-transferability adversarial example generation for the black-box vision transformer

中文摘要英文摘要

目前已经存在针对卷积神经网络的基于迁移的对抗攻击方法,其利用不同模型学习同一任务时往往具有相似决策边界的特点,通过攻击替代模型生成目标模型的对抗样本.但由于架构特性的区别,现有方法难以跨架构地生成对抗样本.针对上述问题,提出了一种基于Vision Transformer(ViT)的高迁移性黑盒对抗样本生成方法OptiEncode,鉴于ViT识别关键特征的优秀能力,利用Grad-CAM算法识别图像中的跨架构重合的关键区域,同时利用Sobel算法识别架构无关的高频区域,仅在关键高频区域添加扰动,从而提升对抗样本的迁移性.与现有侧重模型内部改造的 SE、PNA、FPR 等方法不同,OptiEncode 从输入空间显式对齐跨架构共享特征,机制上正交可叠加于上述方法.在多种架构的黑盒目标模型上进行对抗攻击,OptiEncode在ViT间的黑盒迁移对抗攻击成功率平均提升约10%,在跨架构攻击中的对抗攻击成功率最高提升15%,这表明从输入空间显式对齐"共识区域∩高频结构"能够有效缓解跨架构迁移的性能落差,为提升黑盒迁移攻击的实用性提供了一种可复用的补充路径.

Transfer-based adversarial attacks against convolutional neural networks(CNNs)exploit the observation that models trained on the same task often share similar decision boundaries,crafting examples on a substitute model that transfer to a target.However,due to architectural differences,existing methods struggle to achieve cross-architecture transfer.To address this,we propose the OptiEncode,a Vision Transformer(ViT)‒based method for generating high-transferability black-box adversarial examples.Leverag-ing ViT's strong capability to localize salient features,OptiEncode uses Grad-CAM to identify cross-architecture consensus regions and Sobel to extract architecture-agnostic high-frequency structures,and then injects perturbations only on their intersection to enhance transferability.Unlike SE,PNA,and FPR,which primarily modify the model internals,the OptiEncode explicitly aligns cross-architecture shared features in the input space,thus making it orthogonal and stackable with those approaches.Evaluations on black-box targets across diverse architectures(ViT,CNN,and MLP)show that the OptiEncode improves ViT-to-ViT transfer by about 10%on average and achieves up to 15%gains in cross-architecture settings(e.g.,ViT→CNN).These results indicate that explicitly aligning the"consensus regions ∩ high-frequency structures"in the input space effectively narrows the cross-architecture transfer gap and offers a reusable,complementary path for improving the practicality of black-box transfer attacks.

康行铠;刘洪毅;周慧鹏;王亚杰;祝烈煌

北京理工大学 网络空间安全学院,北京 100081||山东省能源工业互联网大数据技术重点实验室,山东 济南 250003北京理工大学 网络空间安全学院,北京 100081||山东省能源工业互联网大数据技术重点实验室,山东 济南 250003北京理工大学 网络空间安全学院,北京 100081北京理工大学 网络空间安全学院,北京 100081北京理工大学 网络空间安全学院,北京 100081

信息技术与安全科学

对抗样本迁移性黑盒攻击深度学习

adversarial exampletransferabilityblack-box attacksdeep learning

《西安电子科技大学学报(自然科学版)》 2026 (3)

120-134,15

云南省科技计划项目云南省大数据技术及应用创新中心资助(202605AK340003)云南省重大科技专项计划(202502AD080008)云南省新型研发机构培育对象项目(202404BQ040148)

10.19665/j.issn1001-2400.20260402

评论