Enhance Transferability of Adversarial Examples with Model Architecture
Mingyuan Fan (Fuzhou University); Wenzhong Guo (Fuzhou University); Zuobin Ying (Anhui University); Ximeng Liu (Fuzhou University)
-
SPS
IEEE Members: $11.00
Non-members: $15.00
Transferability of adversarial examples is of critical importance to launch black-box adversarial attacks, where attackers are only allowed to access the output of the target model. However, under such a challenging but practical setting, the crafted adversarial examples are prone to overfit the proxy model, presenting poor transferability. In this paper, we suggest alleviating the overfitting issue from a novel perspective, i.e., designing a fitted model architecture. Specifically, delving the bottom of the cause of poor transferability, we arguably decompose and reconstruct the existing model architecture into an effective model architecture, namely multi-track model architecture (MMA). The adversarial examples via MMA can greatly relieve the influence of model-specified features and toward the vulnerable directions adopted by diverse architectures. Extensive experiments demonstrate that the transferability of adversarial examples can be greatly raised.