FACL-Attack: Frequency-Aware Contrastive Learning for Transferable Adversarial Attacks
Abstract: Deep neural networks are known to be vulnerable to security risks due to the inherent transferable nature of adversarial examples. Despite the success of recent generative model-based attacks demonstrating strong transferability, it still remains a challenge to design an efficient attack strategy in a real-world strict black-box setting, where both the target domain and model architectures are unknown. In this paper, we seek to explore a feature contrastive approach in the frequency domain to generate adversarial examples that are robust in both cross-domain and cross-model settings. With that goal in mind, we propose two modules that are only employed during the training phase: a Frequency-Aware Domain Randomization (FADR) module to randomize domain-variant low- and high-range frequency components and a Frequency-Augmented Contrastive Learning (FACL) module to effectively separate domain-invariant mid-frequency features of clean and perturbed image. We demonstrate strong transferability of our generated adversarial perturbations through extensive cross-domain and cross-model experiments, while keeping the inference time complexity.
- Leveraging Local Patch Differences in Multi-Object Scenes for Generative Adversarial Attacks. In Proceedings of the IEEE/CVF Winter Conference on Applications of Computer Vision (WACV).
- Gama: Generative adversarial multi-object scene attacks. Advances in Neural Information Processing Systems (NeurIPS).
- Destruction and Construction Learning for Fine-Grained Image Recognition. In CVPR.
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks. In International Conference on Machine Learning (ICML).
- Boosting adversarial attacks with momentum. In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR).
- An Image is Worth 16x16 Words: Transformers for Image Recognition at Scale. ICLR.
- Advdrop: Adversarial attack to dnns by dropping information. In Proceedings of the IEEE/CVF International Conference on Computer Vision (ICCV).
- A study of the effect of jpg compression on adversarial images. arXiv preprint arXiv:1608.00853.
- Generative adversarial networks. Communications of the ACM, 63(11): 139–144.
- Explaining and Harnessing Adversarial Examples. In International Conference on Learning Representations (ICLR).
- Low Frequency Adversarial Perturbation. In Globerson, A.; and Silva, R., eds., Proceedings of the Thirty-Fifth Conference on Uncertainty in Artificial Intelligence (UAI), volume 115 of Proceedings of Machine Learning Research, 1127–1137. AUAI Press.
- Countering adversarial images using input transformations. arXiv preprint arXiv:1711.00117.
- Deep Residual Learning for Image Recognition. In CVPR.
- Searching for mobilenetv3. In Proceedings of the IEEE/CVF International Conference on Computer Vision (ICCV).
- Squeeze-and-excitation networks. In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR).
- Densely Connected Convolutional Networks. In CVPR.
- Fsdr: Frequency space domain randomization for domain generalization. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR).
- Doubly Contrastive End-to-End Semantic Segmentation for Autonomous Driving under Adverse Weather. In British Machine Vision Conference (BMVC).
- Contrastive adaptation network for unsupervised domain adaptation. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR).
- Selfreg: Self-supervised contrastive regularization for domain generalization. In Proceedings of the IEEE/CVF International Conference on Computer Vision (ICCV).
- Adam: A Method for Stochastic Optimization. In ICLR.
- 3D Object Representations for Fine-Grained Categorization. In IEEE International Conference on Computer Vision Workshop (ICCVW).
- A ConvNet for the 2020s. Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR).
- Frequency domain model augmentation for adversarial attack. In European Conference on Computer Vision (ECCV).
- Detecting autoattack perturbations in the frequency domain. arXiv preprint arXiv:2111.08785.
- Enhancing Cross-Task Black-Box Transferability of Adversarial Examples With Dispersion Reduction. In CVPR.
- Frequency-driven imperceptible adversarial attack on semantic similarity. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR).
- Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083.
- A frequency perspective of adversarial robustness. arXiv preprint arXiv:2111.00861.
- Fine-Grained Visual Classification of Aircraft. ArXiv, abs/1306.5151.
- Learning transferable adversarial perturbations. Advances in Neural Information Processing Systems (NeurIPS).
- On generating transferable targeted perturbations. In Proceedings of the IEEE/CVF International Conference on Computer Vision (ICCV).
- A Self-supervised Approach for Adversarial Robustness. In CVPR.
- Cross-domain transferability of adversarial perturbations. Advances in Neural Information Processing Systems (NeurIPS).
- Generative adversarial perturbations. In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR).
- ImageNet Large Scale Visual Recognition Challenge. IJCV.
- On the Effectiveness of Low Frequency Perturbations. In IJCAI.
- Very Deep Convolutional Networks for Large-Scale Image Recognition. In ICLR.
- Rethinking the Inception Architecture for Computer Vision. In CVPR.
- Mnasnet: Platform-aware neural architecture search for mobile. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR).
- On the structural sensitivity of deep convolutional networks to the directions of fourier basis functions. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR).
- The Caltech-UCSD Birds-200-2011 Dataset. Technical report, California Institute of Technology.
- High-frequency component helps explain the generalization of convolutional neural networks. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR).
- Cross-domain contrastive learning for unsupervised domain adaptation. IEEE Transactions on Multimedia.
- Towards frequency-based explanation for robust cnn. arXiv preprint arXiv:2005.03141.
- Boosting the transferability of adversarial samples via attention. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR).
- Improving transferability of adversarial examples with input diversity. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR).
- A fourier-based framework for domain generalization. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR).
- Contrastive learning assisted-alignment for partial domain adaptation. IEEE Transactions on Neural Networks and Learning Systems.
- Fda: Fourier domain adaptation for semantic segmentation. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR).
- A fourier perspective on model robustness in computer vision. Advances in Neural Information Processing Systems (NeurIPS).
- Wide residual networks. In British Machine Vision Conference (BMVC).
- Beyond imagenet attack: Towards crafting adversarial examples for black-box domains. arXiv preprint arXiv:2201.11528.
Paper Prompts
Sign up for free to create and run prompts on this paper using GPT-5.
Top Community Prompts
Collections
Sign up for free to add this paper to one or more collections.