基于全局先验引导的对抗样本生成方法
网络出版日期: 2026-05-06
基金资助
教育部“春晖计划”(HZKY20220291);中央高校基本科研业务费资助(501XYGG2025139018)
版权
Global prior-guided adversarial example generation method
Online published: 2026-05-06
Copyright
深度神经网络在视觉任务中表现卓越,但易受对抗样本威胁。对抗样本在视觉上对人类几乎不可察觉,却能显著误导模型并危及系统安全;其迁移性使攻击者无需了解目标模型结构与参数即可实施有效攻击。已有方法虽在提升迁移性上取得进展,但生成扰动过度依赖短期即时局部梯度,缺乏全局先验约束,导致更新方向不稳,限制样本质量与跨模型泛化能力。因此,提出一种基于全局先验引导的对抗样本生成方法,在初始阶段利用早期扰动信息,形成全局先验以稳定梯度更新,从而更有效地突破目标模型的决策边界,显著提升对抗样本的生成质量。该方法不仅增强黑盒攻击的迁移性,还可集成至已有基于梯度的攻击框架。实验结果表明,在以基于输入变换与基于梯度的攻击方法作为基础方法时,该方法攻击成功率分别提升15.80%和15.60%,同时保持扰动的不可感知性。
席亮 , 汪宇航 , 张力 , 王天博 . 基于全局先验引导的对抗样本生成方法[J]. 网络空间安全科学学报, 2025 , 3(6) : 90 -99 . DOI: 10.20172/j.issn.2097-3136.250607
Deep neural networks have demonstrated remarkable performance in visual tasks but remain vulnerable to adversarial examples. Such examples are visually imperceptible to humans yet can significantly mislead models and threaten system security. Their transferability further enables attackers to launch effective attacks without knowing the structure or parameters of the target model. Although existing approaches have made progress in improving transferability, they often rely excessively on short-term, local gradients while lacking global prior constraints. This leads to unstable update directions, limiting both the quality of adversarial examples and their cross-model generalization. To address this issue, this paper proposes a global prior-guided adversarial example generation method. By leveraging early perturbation information in the initial stage, the method constructs a global prior to stabilize gradient updates, thereby facilitating more effective traversal of the target model’s decision boundary and significantly improving the quality of adversarial examples. The proposed method not only enhances the transferability of black-box attacks but can also be seamlessly integrated into existing gradient-based attack frameworks. Experimental results show that, when using input transformation–based and gradient-based attack methods as the baselines, the proposed method increases the attack success rate by up to 15.80% and 15.60%, respectively, while keeping the perturbations imperceptible.
| 算法1 GPAE算法(以MI-FGSM为例) |
| 输入:具有真实标签y的干净图片x,交叉熵损失函数L,模型参数为θ。对抗样本扰动上界ε;最大步数T;动量系数μ;最大迭代数S。 输出:xadv。 1:α = ε /T 2:for j = 0,1,···,S−1 do 3: g0 = 0 4: for t = 0,1,···,T−1 do 5: 当j = 0时,通过式(6)、式(7)计算梯度,然后通过式(8)更新 6: 当j >0时,通过式(10)、式(11)得到加噪方向,然后通过式(12)更新 7:返回xadv = |
表 1 本文方法与基于输入变换的攻击方法的攻击成功率Table 1 Attack success rate of input transformation-based attack methods and our method |
| 源模型 | 攻击方法 | 目标模型 | ||||||
| ResNet-50 | ResNet-152 | VGG-19 | DensNet-121 | Inception-v3 | Inception-v4 | IncRes-v2 | ||
| Inception-v3 | DIM | 66.30% | 56.50% | 65.90% | 67.90% | 99.60% | 70.90% | 68.30% |
| DIM-GPAE | 68.50% | 62.50% | 70.90% | 73.30% | 100.00% | 77.40% | 73.30% | |
| TIM | 45.90% | 38.10% | 49.30% | 53.60% | 98.30% | 53.10% | 47.10% | |
| TIM-GPAE | 51.60% | 42.50% | 55.70% | 59.90% | 100.00% | 60.50% | 53.80% | |
| Admix | 71.60% | 66.50% | 73.40% | 73.60% | 99.90% | 78.40% | 75.70% | |
| Admix-GPAE | 75.40% | 70.40% | 76.30% | 77.60% | 100.00% | 82.20% | 78.70% | |
| BSR | 87.90% | 78.30% | 89.50% | 90.10% | 99.60% | 87.30% | 83.80% | |
| BSR-GPAE | 92.30% | 85.60% | 92.10% | 95.00% | 100.00% | 93.80% | 90.60% | |
| IncRes-v2 | DIM | 62.60% | 58.00% | 65.80% | 63.20% | 71.10% | 68.00% | 94.30% |
| DIM-GPAE | 74.00% | 69.90% | 76.50% | 76.60% | 82.40% | 80.20% | 99.00% | |
| TIM | 47.70% | 41.10% | 49.10% | 54.10% | 56.20% | 52.90% | 86.50% | |
| TIM-GPAE | 60.00% | 52.90% | 60.00% | 66.10% | 72.00% | 65.10% | 96.50% | |
| Admix | 72.10% | 67.50% | 71.90% | 72.80% | 78.60% | 75.60% | 96.60% | |
| Admix-GPAE | 82.50% | 77.20% | 81.20% | 82.40% | 88.20% | 84.90% | 99.10% | |
| BSR | 90.10% | 83.00% | 89.50% | 91.30% | 91.90% | 89.50% | 98.60% | |
| BSR-GPAE | 94.10% | 88.30% | 93.30% | 95.50% | 95.10% | 93.10% | 99.20% | |
| DenseNet-121 | DIM | 93.50% | 90.70% | 93.20% | 100.00% | 83.90% | 83.10% | 76.50% |
| DIM-GPAE | 98.00% | 96.20% | 97.90% | 100.00% | 87.90% | 90.60% | 84.30% | |
| TIM | 81.60% | 72.10% | 79.00% | 100.00% | 67.50% | 68.80% | 58.10% | |
| TIM-GPAE | 88.20% | 81.40% | 84.40% | 100.00% | 75.70% | 75.90% | 69.20% | |
| Admix | 95.90% | 91.90% | 95.30% | 99.90% | 82.50% | 82.10% | 72.30% | |
| Admix-GPAE | 97.40% | 95.20% | 97.60% | 100.00% | 84.90% | 86.20% | 78.50% | |
| BSR | 97.90% | 94.50% | 98.90% | 100.00% | 91.70% | 93.50% | 85.20% | |
| BSR-GPAE | 99.50% | 98.80% | 99.80% | 100.00% | 96.00% | 97.80% | 92.40% | |
表 2 本文方法与基于梯度的攻击方法的攻击成功率Table 2 Attack success rate of gradient-based attack methods and our method |
| 源模型 | 攻击方法 | 目标模型 | ||||||
| ResNet-50 | ResNet-152 | VGG-19 | DenseNet-121 | Inception-v3 | Inception-v4 | IncRes-v2 | ||
| Inception-v3 | MI-FGSM | 51.20% | 41.80% | 53.50% | 51.60% | 100.00% | 49.30% | 46.30% |
| MI-FGSM-GPAE | 53.50% | 43.80% | 59.40% | 55.40% | 100.00% | 52.80% | 51.60% | |
| NI-FGSM | 61.50% | 50.00% | 63.20% | 59.80% | 100.00% | 60.30% | 57.50% | |
| NI-FGSM-GPAE | 66.70% | 54.30% | 66.00% | 66.70% | 100.00% | 65.20% | 63.10% | |
| SINI-FGSM | 73.10% | 67.20% | 73.00% | 75.10% | 100.00% | 75.60% | 75.70% | |
| SINI-FGSM-GPAE | 79.50% | 72.80% | 79.40% | 81.50% | 100.00% | 83.50% | 81.50% | |
| VMI-FGSM | 64.90% | 57.20% | 65.90% | 67.40% | 100.00% | 70.40% | 69.10% | |
| VMI-FGSM-GPAE | 75.90% | 70.30% | 76.30% | 75.90% | 100.00% | 81.30% | 77.70% | |
| VNI-FGSM | 72.30% | 64.90% | 71.70% | 73.50% | 100.00% | 78.00% | 75.60% | |
| VNI-FGSM-GPAE | 82.00% | 78.90% | 82.50% | 82.90% | 100.00% | 88.30% | 85.90% | |
| GI-FGSM | 75.70% | 69.70% | 73.40% | 76.00% | 99.60% | 81.90% | 79.90% | |
| GI-FGSM-GPAE | 84.90% | 81.50% | 85.90% | 83.80% | 100.00% | 89.00% | 88.30% | |
| GAA | 79.80% | 74.70% | 79.40% | 80.90% | 99.70% | 85.60% | 85.20% | |
| GAA-GPAE | 90.90% | 87.20% | 88.90% | 89.50% | 100.00% | 93.80% | 92.40% | |
| IncRes-v2 | MI-FGSM | 53.50% | 45.90% | 56.40% | 50.50% | 56.10% | 51.00% | 97.50% |
| MI-FGSM-GPAE | 61.40% | 51.60% | 64.90% | 58.60% | 63.60% | 56.80% | 99.70% | |
| NI-FGSM | 57.80% | 47.00% | 62.40% | 53.50% | 57.60% | 53.90% | 98.70% | |
| NI-FGSM-GPAE | 63.80% | 53.20% | 68.40% | 61.50% | 66.30% | 60.60% | 100.00% | |
| SINI-FGSM | 76.40% | 72.00% | 76.40% | 76.90% | 85.10% | 80.90% | 99.30% | |
| SINI-FGSM-GPAE | 85.70% | 79.30% | 84.00% | 85.40% | 90.30% | 86.70% | 100.00% | |
| VMI-FGSM | 65.90% | 61.70% | 68.70% | 67.10% | 74.90% | 69.60% | 98.20% | |
| VMI-FGSM-GPAE | 79.30% | 76.50% | 81.50% | 81.50% | 87.00% | 85.00% | 99.40% | |
| VNI-FGSM | 70.80% | 65.60% | 72.40% | 70.80% | 77.50% | 73.40% | 98.20% | |
| VNI-FGSM-GPAE | 83.90% | 80.60% | 85.10% | 85.80% | 89.70% | 89.00% | 99.70% | |
| GI-FGSM | 74.10% | 69.30% | 74.00% | 73.30% | 79.00% | 77.50% | 97.10% | |
| GI-FGSM-GPAE | 85.20% | 81.80% | 86.40% | 87.00% | 88.50% | 90.30% | 98.00% | |
| GAA | 77.20% | 75.00% | 77.20% | 76.80% | 84.00% | 83.40% | 94.60% | |
| GAA-GPAE | 89.40% | 86.20% | 90.10% | 91.30% | 92.30% | 94.70% | 98.90% | |
| DenseNet-121 | MI-FGSM | 87.00% | 79.60% | 85.20% | 100.00% | 64.50% | 62.90% | 54.30% |
| MI-FGSM-GPAE | 91.00% | 85.10% | 89.90% | 100.00% | 68.20% | 68.60% | 58.20% | |
| NI-FGSM | 92.30% | 85.20% | 90.70% | 100.00% | 69.00% | 67.10% | 59.30% | |
| NI-FGSM-GPAE | 95.30% | 91.90% | 95.90% | 100.00% | 74.50% | 75.20% | 64.00% | |
| SINI-FGSM | 96.40% | 92.00% | 95.20% | 100.00% | 83.30% | 83.10% | 76.30% | |
| SINI-FGSM-GPAE | 98.70% | 97.00% | 97.80% | 100.00% | 88.80% | 89.70% | 82.30% | |
| VMI-FGSM | 94.50% | 91.50% | 93.90% | 100.00% | 80.10% | 82.70% | 74.10% | |
| VMI-FGSM-GPAE | 98.80% | 97.70% | 98.90% | 100.00% | 89.80% | 92.00% | 85.30% | |
| VNI-FGSM | 97.50% | 93.50% | 95.70% | 100.00% | 83.50% | 84.30% | 77.00% | |
| VNI-FGSM-GPAE | 99.70% | 98.70% | 99.30% | 100.00% | 91.90% | 94.10% | 87.80% | |
| GI-FGSM | 98.00% | 94.60% | 96.90% | 100.00% | 85.90% | 88.40% | 81.90% | |
| GI-FGSM-GPAE | 98.60% | 96.00% | 97.90% | 100.00% | 92.30% | 93.90% | 90.50% | |
| GAA | 98.90% | 97.30% | 98.40% | 100.00% | 93.80% | 93.40% | 89.60% | |
| GAA-GPAE | 99.00% | 97.40% | 98.00% | 100.00% | 95.90% | 94.00% | 93.20% | |
表 3 本文方法与VNI-FGSM面对7种防御机制时的攻击成功率Table 3 Attack success-rates between the VNI-FGSM and VNI-FGSM-GPAE against seven defenses |
| 攻击方法 | R&P | Bit-Red | FD | JPEG | NRP | RS | DiffPure | 平均 |
| VNI-FGSM | 73.00% | 71.00% | 73.50% | 68.20% | 43.80% | 30.40% | 17.30% | 53.89% |
| VNI-FGSM-GPAE | 86.50% | 86.20% | 88.30% | 84.00% | 58.90% | 39.70% | 26.50% | 67.16% |
| 1 |
Goodfellow I J, Shlens J, Szegedy C. Explaining and harnessing adversarial examples[C]//International Conference on Learning Representations, San Diego: 2015. 1-11.
|
| 2 |
Szegedy C, Zaremba W, Sutskever I, et al. Intriguing properties of neural networks[C]//International Conference on Learning Representations, Banff: ICLR, 2014: 1-10.
|
| 3 |
Kong Z L, Guo J F, Li A, et al. PhysGAN: generating physical-world-resilient adversarial examples for autonomous driving[C]//Proceedings of the 2020 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR). Piscataway: IEEE Press, 2020: 14242-14251.
|
| 4 |
Qi L F, Wang H B, Zhang J Q, et al. Unsupervised domain adaptive person search via dual self-calibration[J]. Proceedings of the AAAI Conference on Artificial Intelligence, 2025, 39 (6): 6550- 6558.
|
| 5 |
Madry A, Makelov A, Schmidt L, et al. Towards deep learning models resistant to adversarial attacks[C]//International Conference on Learning Representations, Toulon, 2018.
|
| 6 |
Dong Y P, Liao F Z, Pang T Y, et al. Boosting adversarial attacks with momentum[C]//Proceedings of the 2018 IEEE/CVF Conference on Computer Vision and Pattern Recognition. Piscataway: IEEE Press, 2018: 9185-9193.
|
| 7 |
Wang K Y, He X R, Wang W X, et al. Boosting adversarial transferability by block shuffle and rotation[C]//Proceedings of the 2024 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) . Piscataway: IEEE Press, 2024: 24336-24346.
|
| 8 |
Wang X S, He K. Enhancing the transferability of adversarial attacks through variance tuning[C]//Proceedings of the 2021 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) . Piscataway: IEEE Press, 2021: 1924-1933.
|
| 9 |
Zhu R Y, Zhang Z L, Liu Z, et al. Learning to transform dynamically for better adversarial transferability[C]//Proceedings of the 2024 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR). Piscataway: IEEE Press, 2024: 24273-24283.
|
| 10 |
Li Q, Guo Y, Zuo W, et al. Improving adversarial transferability via intermediate-level perturbation decay [C]//Proceedings of the Advances in Neural Information Processing Systems, 2023. 1638-1655.
|
| 11 |
Huang Q, Katsman I, Gu Z Q, et al. Enhancing adversarial example transferability with an intermediate level attack[C]//Proceedings of the 2019 IEEE/CVF International Conference on Computer Vision (ICCV). Piscataway: IEEE Press, 2019: 4732-4741.
|
| 12 |
Chen H, Zhang Y, Dong Y, et al. Rethinking model ensemble in transfer-based adversarial attacks[C]//Proceedings of the International Conference on Learning Representations, Vienna: ICLR, 2024.
|
| 13 |
Xiong Y F, Lin J D, Zhang M, et al. Stochastic variance reduced ensemble adversarial attack for boosting the adversarial transferability[C]//Proceedings of the 2022 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR). Piscataway: IEEE Press, 2022: 14963-14972.
|
| 14 |
Kurakin A, Goodfellow I J, BENGIO S. Adversarial examples in the physical world [C]//Proceedings of the International Conference on Learning Representations (Workshops), Toulon, 2017. 1-14.
|
| 15 |
Lin J, Song C, He K, et al. Nesterov accelerated gradient and scale invariance for adversarial attacks[C]//Proceedings of the International Conference on Learning Representations New or leans: ICLR, 2019. 1-23.
|
| 16 |
Ge Z, Wang X, Liu H, et al. Boosting adversarial transferability by achieving flat local maxima[C]//Proceedings of the Advances in Neural Information Processing Systems, New York: ACM, 2023. 31766-31781.
|
| 17 |
Xie C H, Zhang Z S, Zhou Y Y, et al. Improving transferability of adversarial examples with input diversity[C]//Proceedings of the 2019 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR). Piscataway: IEEE Press, 2019: 2725-2734.
|
| 18 |
Dong Y P, Pang T Y, Su H, et al. Evading defenses to transferable adversarial examples by translation-invariant attacks[C]//Proceedings of the 2019 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR). Piscataway: IEEE Press, 2019: 4307-4316.
|
| 19 |
Wang X S, He X R, Wang J D, et al. Admix: enhancing the transferability of adversarial attacks[C]//Proceedings of the 2021 IEEE/CVF International Conference on Computer Vision (ICCV). Piscataway: IEEE Press, 2021: 16138-16147.
|
| 20 |
Zhou W, Hou X, Chen Y J, et al. Transferable adversarial perturbations[M]. Computer Vision – ECCV 2018. ChamSpringer International Publishing, 2018: 471-486.
|
| 21 |
Wang Z B, Guo H C, Zhang Z F, et al. Feature importance-aware transferable adversarial attacks[C]//Proceedings of the 2021 IEEE/CVF International Conference on Computer Vision (ICCV) . Piscataway: IEEE Press, 2021: 7619-7628.
|
| 22 |
Zhang J P, Wu W B, Huang J T, et al. Improving adversarial transferability via neuron attribution-based attacks[C]//Proceedings of the 2022 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) . Piscataway: IEEE Press, 2022: 14973-14982.
|
| 23 |
Shafahi A, Najibi M, Ghiasi A, et al. Adversarial training for free![C]//Proceedings of the 33rd International Conference on Neural Information Processing Systems. New York: ACM, 2019: 3358-3369.
|
| 24 |
Tramer F, Kurakin A, Papernot N, et al. Ensemble adversarial training: attacks and defenses [C]//Proceedings of the International Conference on Learning Representations, Vancouver: ICLR, 2018. 1-29.
|
| 25 |
Guo C, Rana M, Cisse M, et al. Countering adversarial images using input transformations[C]//Proceedings of the International Conference on Learning Representations, Vancouver: ICLR, 2018. 1-16.
|
| 26 |
Liao F Z, Liang M, Dong Y P, et al. Defense against adversarial attacks using high-level representation guided denoiser[C]//Proceedings of the 2018 IEEE/CVF Conference on Computer Vision and Pattern Recognition. Piscataway: IEEE Press, 2018: 1778-1787.
|
| 27 |
Xie C, Wang J, Zhang Z, et al. Miti-gating adversarial effects through randomization [C]//Proceedings of the International Conference on Learning Representations, Vancouver: ICLR, 2018.
|
| 28 |
Xu W, Evans D, Qi Y. Feature squeezing: detecting adversarial examples in deep neural networks [C]//Proceedings of the Network and Distributed System Security Symposium, San Diego: Internet Society, 2018. 1-15.
|
| 29 |
Naseer M, Khan S, Hayat M, et al. A self-supervised approach for adversarial robustness[C]//Proceedings of the 2020 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR). Piscataway: IEEE Press, 2020: 259-268.
|
| 30 |
Cohen J, Rosenfeld E, Kolter J Z. Certified adversarial robustness via randomized smoothing [C]//Proceedings of the International Conference on Machine Learning, 2019: 1310-1320.
|
| 31 |
Nie W, Guo B, Huang Y, et al. Diffusion models for adversarial purification [C]//Proceedings of the International Conference on Machine Learning, 2022: 16805-16827.
|
| 32 |
Croce F, Hein M. Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks[C]//Proceedings of the 37th International Conference on Machine Learning. New York: ACM, 2020: 2206-2216.
|
| 33 |
Russakovsky O, Deng J, Su H, et al. ImageNet large scale visual recognition challenge[J]. International Journal of Computer Vision, 2015, 115 (3): 211- 252.
|
| 34 |
He K M, Zhang X Y, Ren S Q, et al. Deep residual learning for image recognition[C]//Proceedings of the 2016 IEEE Conference on Computer Vision and Pattern Recognition (CVPR). Piscataway: IEEE Press, 2016: 770-778.
|
| 35 |
Simonyan K. Very deep convolutional networks for large-scale image recognition [C]//Proceedings of the International Conference on Learning Representations, San Diego: ICLR, 2015. 1-14.
|
| 36 |
Huang G, Liu Z, Van Der M L, et al. Densely connected convolutional networks[C]//Proceedings of the 2017 IEEE Conference on Computer Vision and Pattern Recognition (CVPR). Piscataway: IEEE Press, 2017: 2261-2269.
|
| 37 |
Szegedy C, Vanhoucke V, Ioffe S, et al. Rethinking the inception architecture for computer vision[C]//Proceedings of the 2016 IEEE Conference on Computer Vision and Pattern Recognition (CVPR). Piscataway: IEEE Press, 2016: 2818-2826.
|
| 38 |
Szegedy C, Ioffe S, Vanhoucke V, et al. Inception-v4, inception-ResNet and the impact of residual connections on learning[C]//Proceedings of the AAAI Conference on Artificial Intelligence, San Francisco: AAAI Press, 2017, 31: 4278-4285.
|
| 39 |
Wang J F, Chen Z Y, Jiang K X, et al. Boosting the transferability of adversarial attacks with global momentum initialization[J]. Expert Systems with Applications, 2024, 255, 124757.
|
| 40 |
Gan F Q, Wo Y. Boosting the transferability of adversarial examples through gradient aggregation[J]. IEEE Transactions on Information Forensics and Security, 2025, 20, 5563- 5576.
|
| 41 |
Liu Z H, Liu Q, Liu T, et al. Feature distillation: DNN-oriented JPEG compression against adversarial examples[C]//Proceedings of the 2019 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR). Piscataway: IEEE Press, 2019: 860-868.
|
| 42 |
Selvaraju R R, Cogswell M, Das A, et al. Grad-CAM: visual explanations from deep networks via gradient-based localization[C]//Proceedings of the 2017 IEEE International Conference on Computer Vision (ICCV). Piscataway: IEEE Press, 2017: 618-626.
|
/
| 〈 |
|
〉 |