A Transferable Adversarial Example Generation Method Based on Input Diversity and Model Ensemble
DOI:
CSTR:
Author:
Affiliation:

1.School of Computer Science, Nanjing University of Posts and Telecommunications, Nanjing 210023,China; 2.Institute of Network Security and Trusted Computing, Nanjing University of Posts and Telecommunications, Nanjing 210023,China

Clc Number:

Fund Project:

  • Article
  • |
  • Figures
  • |
  • Metrics
  • |
  • Reference
  • |
  • Related
  • |
  • Cited by
  • |
  • Materials
  • |
  • Comments
    Abstract:

    Research on adversarial examples can unearth the robustness flaws of deep learning models, drive the research, development and optimization of defense mechanisms, and thereby enhance the secure application capability of image classification models in real-world scenarios. However, most existing adversarial example attack methods suffer from weak black-box transferability and insufficient generalization of the generated adversarial examples. To address the above issues, this paper proposes a transferable adversarial example generation method named DE-TEG based on input diversity and model ensemble. First, an input diversity enhancement strategy with multi-scale transformation is introduced, which expands the input distribution in the optimization process through random scaling and adaptive padding/cropping operations. This enables adversarial examples to break away from the dependence on specific image scales and positions, learn more generalized gradient information, and improve their robustness to input transformations. Second, a model ensemble group composed of multiple heterogeneous network architectures is constructed. By averaging and fusing the adversarial loss functions of multiple models, adversarial examples are guided to learn cross-model universal adversarial features, thus enhancing their transfer attack performance in black-box scenarios. Finally, a momentum optimization mechanism is incorporated into the iterative optimization process. By accumulating the directional information of historical gradients to form optimization inertia, it effectively stabilizes the direction of parameter update, accelerates the convergence process on complex loss surfaces, and prevents the optimization process from falling into local optima. The experimental results show that, compared with the baseline methods, DE-TEG improves the average success rate of transferable attacks by approximately 3.16% on both datasets.

    Reference
    Related
    Cited by
Get Citation

XU He, ZHANG Heng, LI Peng*, ZHENG Wenlong, ZHU Feng. A Transferable Adversarial Example Generation Method Based on Input Diversity and Model Ensemble[J]. Journal of Data Acquisition and Processing,,().

Copy
Related Videos

Share
Article Metrics
  • Abstract:
  • PDF:
  • HTML:
  • Cited by:
History
  • Received:
  • Revised:
  • Adopted:
  • Online: July 14,2026
  • Published:
Article QR Code