基于输入多样性与模型集成的可迁移对抗样本生成方法
DOI:
作者:
作者单位:

1.南京邮电大学计算机学院,南京 210023; 2.南京邮电大学网络安全与可信计算研究所,南京 210023

作者简介:

通讯作者:

基金项目:


A Transferable Adversarial Example Generation Method Based on Input Diversity and Model Ensemble
Author:
Affiliation:

1.School of Computer Science, Nanjing University of Posts and Telecommunications, Nanjing 210023,China; 2.Institute of Network Security and Trusted Computing, Nanjing University of Posts and Telecommunications, Nanjing 210023,China

Fund Project:

  • 摘要
  • |
  • 图/表
  • |
  • 访问统计
  • |
  • 参考文献
  • |
  • 相似文献
  • |
  • 引证文献
  • |
  • 资源附件
    摘要:

    对抗样本的研究能够挖掘深度学习模型的鲁棒性缺陷,推动防御机制的研发与优化,进而提升图像分类模型在实际场景中的安全应用能力。然而,现有的对抗样本攻击方法大多存在着黑盒迁移能力不强,生成的对抗样本泛化能力不足的问题。为解决上述问题,本文提出了一种基于输入多样性与模型集成的可迁移对抗样本生成方法DE-TEG。首先,引入多尺度变换的输入多样性增强策略,通过随机缩放、自适应填充/裁剪操作扩展优化过程的输入分布,使对抗样本摆脱对特定图像尺度与位置的依赖,学习更具泛化性的梯度信息,提升其对输入变换的鲁棒性;其次,构建由多种异构网络架构组成的模型集成组,通过对多模型的对抗损失函数进行平均融合,引导对抗样本学习跨模型的通用对抗特征,从而提升其在黑盒场景下的迁移攻击性能;最后,在迭代优化过程中引入动量优化机制,通过累积历史梯度的方向信息形成优化惯性,有效稳定参数更新方向,加速复杂损失曲面下的收敛过程,避免优化过程陷入局部最优解。实验结果表明,DE-TEG在两个数据集下相较于对比实验可迁移攻击成功率平均提升约3.16%。

    Abstract:

    Research on adversarial examples can unearth the robustness flaws of deep learning models, drive the research, development and optimization of defense mechanisms, and thereby enhance the secure application capability of image classification models in real-world scenarios. However, most existing adversarial example attack methods suffer from weak black-box transferability and insufficient generalization of the generated adversarial examples. To address the above issues, this paper proposes a transferable adversarial example generation method named DE-TEG based on input diversity and model ensemble. First, an input diversity enhancement strategy with multi-scale transformation is introduced, which expands the input distribution in the optimization process through random scaling and adaptive padding/cropping operations. This enables adversarial examples to break away from the dependence on specific image scales and positions, learn more generalized gradient information, and improve their robustness to input transformations. Second, a model ensemble group composed of multiple heterogeneous network architectures is constructed. By averaging and fusing the adversarial loss functions of multiple models, adversarial examples are guided to learn cross-model universal adversarial features, thus enhancing their transfer attack performance in black-box scenarios. Finally, a momentum optimization mechanism is incorporated into the iterative optimization process. By accumulating the directional information of historical gradients to form optimization inertia, it effectively stabilizes the direction of parameter update, accelerates the convergence process on complex loss surfaces, and prevents the optimization process from falling into local optima. The experimental results show that, compared with the baseline methods, DE-TEG improves the average success rate of transferable attacks by approximately 3.16% on both datasets.

    参考文献
    相似文献
    引证文献
引用本文

徐鹤,张恒,李鹏,郑文龙,朱枫.基于输入多样性与模型集成的可迁移对抗样本生成方法[J].数据采集与处理,,():

复制
分享
文章指标
  • 点击次数:
  • 下载次数:
历史
  • 收稿日期:
  • 最后修改日期:
  • 录用日期:
  • 在线发布日期: 2026-07-14