Global prior-guided adversarial example generation method
Online published: 2026-05-06
Copyright
Deep neural networks have demonstrated remarkable performance in visual tasks but remain vulnerable to adversarial examples. Such examples are visually imperceptible to humans yet can significantly mislead models and threaten system security. Their transferability further enables attackers to launch effective attacks without knowing the structure or parameters of the target model. Although existing approaches have made progress in improving transferability, they often rely excessively on short-term, local gradients while lacking global prior constraints. This leads to unstable update directions, limiting both the quality of adversarial examples and their cross-model generalization. To address this issue, this paper proposes a global prior-guided adversarial example generation method. By leveraging early perturbation information in the initial stage, the method constructs a global prior to stabilize gradient updates, thereby facilitating more effective traversal of the target model’s decision boundary and significantly improving the quality of adversarial examples. The proposed method not only enhances the transferability of black-box attacks but can also be seamlessly integrated into existing gradient-based attack frameworks. Experimental results show that, when using input transformation–based and gradient-based attack methods as the baselines, the proposed method increases the attack success rate by up to 15.80% and 15.60%, respectively, while keeping the perturbations imperceptible.
Xi Liang , Wang Yuhang , Zhang Li , Wang Tianbo . Global prior-guided adversarial example generation method[J]. Journal of Cybersecurity, 2025 , 3(6) : 90 -99 . DOI: 10.20172/j.issn.2097-3136.250607
| 算法1 GPAE算法(以MI-FGSM为例) |
| 输入:具有真实标签y的干净图片x,交叉熵损失函数L,模型参数为θ。对抗样本扰动上界ε;最大步数T;动量系数μ;最大迭代数S。 输出:xadv。 1:α = ε /T 2:for j = 0,1,···,S−1 do 3: g0 = 0 4: for t = 0,1,···,T−1 do 5: 当j = 0时,通过式(6)、式(7)计算梯度,然后通过式(8)更新 6: 当j >0时,通过式(10)、式(11)得到加噪方向,然后通过式(12)更新 7:返回xadv = |
表 1 本文方法与基于输入变换的攻击方法的攻击成功率Table 1 Attack success rate of input transformation-based attack methods and our method |
| 源模型 | 攻击方法 | 目标模型 | ||||||
| ResNet-50 | ResNet-152 | VGG-19 | DensNet-121 | Inception-v3 | Inception-v4 | IncRes-v2 | ||
| Inception-v3 | DIM | 66.30% | 56.50% | 65.90% | 67.90% | 99.60% | 70.90% | 68.30% |
| DIM-GPAE | 68.50% | 62.50% | 70.90% | 73.30% | 100.00% | 77.40% | 73.30% | |
| TIM | 45.90% | 38.10% | 49.30% | 53.60% | 98.30% | 53.10% | 47.10% | |
| TIM-GPAE | 51.60% | 42.50% | 55.70% | 59.90% | 100.00% | 60.50% | 53.80% | |
| Admix | 71.60% | 66.50% | 73.40% | 73.60% | 99.90% | 78.40% | 75.70% | |
| Admix-GPAE | 75.40% | 70.40% | 76.30% | 77.60% | 100.00% | 82.20% | 78.70% | |
| BSR | 87.90% | 78.30% | 89.50% | 90.10% | 99.60% | 87.30% | 83.80% | |
| BSR-GPAE | 92.30% | 85.60% | 92.10% | 95.00% | 100.00% | 93.80% | 90.60% | |
| IncRes-v2 | DIM | 62.60% | 58.00% | 65.80% | 63.20% | 71.10% | 68.00% | 94.30% |
| DIM-GPAE | 74.00% | 69.90% | 76.50% | 76.60% | 82.40% | 80.20% | 99.00% | |
| TIM | 47.70% | 41.10% | 49.10% | 54.10% | 56.20% | 52.90% | 86.50% | |
| TIM-GPAE | 60.00% | 52.90% | 60.00% | 66.10% | 72.00% | 65.10% | 96.50% | |
| Admix | 72.10% | 67.50% | 71.90% | 72.80% | 78.60% | 75.60% | 96.60% | |
| Admix-GPAE | 82.50% | 77.20% | 81.20% | 82.40% | 88.20% | 84.90% | 99.10% | |
| BSR | 90.10% | 83.00% | 89.50% | 91.30% | 91.90% | 89.50% | 98.60% | |
| BSR-GPAE | 94.10% | 88.30% | 93.30% | 95.50% | 95.10% | 93.10% | 99.20% | |
| DenseNet-121 | DIM | 93.50% | 90.70% | 93.20% | 100.00% | 83.90% | 83.10% | 76.50% |
| DIM-GPAE | 98.00% | 96.20% | 97.90% | 100.00% | 87.90% | 90.60% | 84.30% | |
| TIM | 81.60% | 72.10% | 79.00% | 100.00% | 67.50% | 68.80% | 58.10% | |
| TIM-GPAE | 88.20% | 81.40% | 84.40% | 100.00% | 75.70% | 75.90% | 69.20% | |
| Admix | 95.90% | 91.90% | 95.30% | 99.90% | 82.50% | 82.10% | 72.30% | |
| Admix-GPAE | 97.40% | 95.20% | 97.60% | 100.00% | 84.90% | 86.20% | 78.50% | |
| BSR | 97.90% | 94.50% | 98.90% | 100.00% | 91.70% | 93.50% | 85.20% | |
| BSR-GPAE | 99.50% | 98.80% | 99.80% | 100.00% | 96.00% | 97.80% | 92.40% | |
表 2 本文方法与基于梯度的攻击方法的攻击成功率Table 2 Attack success rate of gradient-based attack methods and our method |
| 源模型 | 攻击方法 | 目标模型 | ||||||
| ResNet-50 | ResNet-152 | VGG-19 | DenseNet-121 | Inception-v3 | Inception-v4 | IncRes-v2 | ||
| Inception-v3 | MI-FGSM | 51.20% | 41.80% | 53.50% | 51.60% | 100.00% | 49.30% | 46.30% |
| MI-FGSM-GPAE | 53.50% | 43.80% | 59.40% | 55.40% | 100.00% | 52.80% | 51.60% | |
| NI-FGSM | 61.50% | 50.00% | 63.20% | 59.80% | 100.00% | 60.30% | 57.50% | |
| NI-FGSM-GPAE | 66.70% | 54.30% | 66.00% | 66.70% | 100.00% | 65.20% | 63.10% | |
| SINI-FGSM | 73.10% | 67.20% | 73.00% | 75.10% | 100.00% | 75.60% | 75.70% | |
| SINI-FGSM-GPAE | 79.50% | 72.80% | 79.40% | 81.50% | 100.00% | 83.50% | 81.50% | |
| VMI-FGSM | 64.90% | 57.20% | 65.90% | 67.40% | 100.00% | 70.40% | 69.10% | |
| VMI-FGSM-GPAE | 75.90% | 70.30% | 76.30% | 75.90% | 100.00% | 81.30% | 77.70% | |
| VNI-FGSM | 72.30% | 64.90% | 71.70% | 73.50% | 100.00% | 78.00% | 75.60% | |
| VNI-FGSM-GPAE | 82.00% | 78.90% | 82.50% | 82.90% | 100.00% | 88.30% | 85.90% | |
| GI-FGSM | 75.70% | 69.70% | 73.40% | 76.00% | 99.60% | 81.90% | 79.90% | |
| GI-FGSM-GPAE | 84.90% | 81.50% | 85.90% | 83.80% | 100.00% | 89.00% | 88.30% | |
| GAA | 79.80% | 74.70% | 79.40% | 80.90% | 99.70% | 85.60% | 85.20% | |
| GAA-GPAE | 90.90% | 87.20% | 88.90% | 89.50% | 100.00% | 93.80% | 92.40% | |
| IncRes-v2 | MI-FGSM | 53.50% | 45.90% | 56.40% | 50.50% | 56.10% | 51.00% | 97.50% |
| MI-FGSM-GPAE | 61.40% | 51.60% | 64.90% | 58.60% | 63.60% | 56.80% | 99.70% | |
| NI-FGSM | 57.80% | 47.00% | 62.40% | 53.50% | 57.60% | 53.90% | 98.70% | |
| NI-FGSM-GPAE | 63.80% | 53.20% | 68.40% | 61.50% | 66.30% | 60.60% | 100.00% | |
| SINI-FGSM | 76.40% | 72.00% | 76.40% | 76.90% | 85.10% | 80.90% | 99.30% | |
| SINI-FGSM-GPAE | 85.70% | 79.30% | 84.00% | 85.40% | 90.30% | 86.70% | 100.00% | |
| VMI-FGSM | 65.90% | 61.70% | 68.70% | 67.10% | 74.90% | 69.60% | 98.20% | |
| VMI-FGSM-GPAE | 79.30% | 76.50% | 81.50% | 81.50% | 87.00% | 85.00% | 99.40% | |
| VNI-FGSM | 70.80% | 65.60% | 72.40% | 70.80% | 77.50% | 73.40% | 98.20% | |
| VNI-FGSM-GPAE | 83.90% | 80.60% | 85.10% | 85.80% | 89.70% | 89.00% | 99.70% | |
| GI-FGSM | 74.10% | 69.30% | 74.00% | 73.30% | 79.00% | 77.50% | 97.10% | |
| GI-FGSM-GPAE | 85.20% | 81.80% | 86.40% | 87.00% | 88.50% | 90.30% | 98.00% | |
| GAA | 77.20% | 75.00% | 77.20% | 76.80% | 84.00% | 83.40% | 94.60% | |
| GAA-GPAE | 89.40% | 86.20% | 90.10% | 91.30% | 92.30% | 94.70% | 98.90% | |
| DenseNet-121 | MI-FGSM | 87.00% | 79.60% | 85.20% | 100.00% | 64.50% | 62.90% | 54.30% |
| MI-FGSM-GPAE | 91.00% | 85.10% | 89.90% | 100.00% | 68.20% | 68.60% | 58.20% | |
| NI-FGSM | 92.30% | 85.20% | 90.70% | 100.00% | 69.00% | 67.10% | 59.30% | |
| NI-FGSM-GPAE | 95.30% | 91.90% | 95.90% | 100.00% | 74.50% | 75.20% | 64.00% | |
| SINI-FGSM | 96.40% | 92.00% | 95.20% | 100.00% | 83.30% | 83.10% | 76.30% | |
| SINI-FGSM-GPAE | 98.70% | 97.00% | 97.80% | 100.00% | 88.80% | 89.70% | 82.30% | |
| VMI-FGSM | 94.50% | 91.50% | 93.90% | 100.00% | 80.10% | 82.70% | 74.10% | |
| VMI-FGSM-GPAE | 98.80% | 97.70% | 98.90% | 100.00% | 89.80% | 92.00% | 85.30% | |
| VNI-FGSM | 97.50% | 93.50% | 95.70% | 100.00% | 83.50% | 84.30% | 77.00% | |
| VNI-FGSM-GPAE | 99.70% | 98.70% | 99.30% | 100.00% | 91.90% | 94.10% | 87.80% | |
| GI-FGSM | 98.00% | 94.60% | 96.90% | 100.00% | 85.90% | 88.40% | 81.90% | |
| GI-FGSM-GPAE | 98.60% | 96.00% | 97.90% | 100.00% | 92.30% | 93.90% | 90.50% | |
| GAA | 98.90% | 97.30% | 98.40% | 100.00% | 93.80% | 93.40% | 89.60% | |
| GAA-GPAE | 99.00% | 97.40% | 98.00% | 100.00% | 95.90% | 94.00% | 93.20% | |
表 3 本文方法与VNI-FGSM面对7种防御机制时的攻击成功率Table 3 Attack success-rates between the VNI-FGSM and VNI-FGSM-GPAE against seven defenses |
| 攻击方法 | R&P | Bit-Red | FD | JPEG | NRP | RS | DiffPure | 平均 |
| VNI-FGSM | 73.00% | 71.00% | 73.50% | 68.20% | 43.80% | 30.40% | 17.30% | 53.89% |
| VNI-FGSM-GPAE | 86.50% | 86.20% | 88.30% | 84.00% | 58.90% | 39.70% | 26.50% | 67.16% |
| 1 |
Goodfellow I J, Shlens J, Szegedy C. Explaining and harnessing adversarial examples[C]//International Conference on Learning Representations, San Diego: 2015. 1-11.
|
| 2 |
Szegedy C, Zaremba W, Sutskever I, et al. Intriguing properties of neural networks[C]//International Conference on Learning Representations, Banff: ICLR, 2014: 1-10.
|
| 3 |
Kong Z L, Guo J F, Li A, et al. PhysGAN: generating physical-world-resilient adversarial examples for autonomous driving[C]//Proceedings of the 2020 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR). Piscataway: IEEE Press, 2020: 14242-14251.
|
| 4 |
Qi L F, Wang H B, Zhang J Q, et al. Unsupervised domain adaptive person search via dual self-calibration[J]. Proceedings of the AAAI Conference on Artificial Intelligence, 2025, 39 (6): 6550- 6558.
|
| 5 |
Madry A, Makelov A, Schmidt L, et al. Towards deep learning models resistant to adversarial attacks[C]//International Conference on Learning Representations, Toulon, 2018.
|
| 6 |
Dong Y P, Liao F Z, Pang T Y, et al. Boosting adversarial attacks with momentum[C]//Proceedings of the 2018 IEEE/CVF Conference on Computer Vision and Pattern Recognition. Piscataway: IEEE Press, 2018: 9185-9193.
|
| 7 |
Wang K Y, He X R, Wang W X, et al. Boosting adversarial transferability by block shuffle and rotation[C]//Proceedings of the 2024 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) . Piscataway: IEEE Press, 2024: 24336-24346.
|
| 8 |
Wang X S, He K. Enhancing the transferability of adversarial attacks through variance tuning[C]//Proceedings of the 2021 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) . Piscataway: IEEE Press, 2021: 1924-1933.
|
| 9 |
Zhu R Y, Zhang Z L, Liu Z, et al. Learning to transform dynamically for better adversarial transferability[C]//Proceedings of the 2024 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR). Piscataway: IEEE Press, 2024: 24273-24283.
|
| 10 |
Li Q, Guo Y, Zuo W, et al. Improving adversarial transferability via intermediate-level perturbation decay [C]//Proceedings of the Advances in Neural Information Processing Systems, 2023. 1638-1655.
|
| 11 |
Huang Q, Katsman I, Gu Z Q, et al. Enhancing adversarial example transferability with an intermediate level attack[C]//Proceedings of the 2019 IEEE/CVF International Conference on Computer Vision (ICCV). Piscataway: IEEE Press, 2019: 4732-4741.
|
| 12 |
Chen H, Zhang Y, Dong Y, et al. Rethinking model ensemble in transfer-based adversarial attacks[C]//Proceedings of the International Conference on Learning Representations, Vienna: ICLR, 2024.
|
| 13 |
Xiong Y F, Lin J D, Zhang M, et al. Stochastic variance reduced ensemble adversarial attack for boosting the adversarial transferability[C]//Proceedings of the 2022 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR). Piscataway: IEEE Press, 2022: 14963-14972.
|
| 14 |
Kurakin A, Goodfellow I J, BENGIO S. Adversarial examples in the physical world [C]//Proceedings of the International Conference on Learning Representations (Workshops), Toulon, 2017. 1-14.
|
| 15 |
Lin J, Song C, He K, et al. Nesterov accelerated gradient and scale invariance for adversarial attacks[C]//Proceedings of the International Conference on Learning Representations New or leans: ICLR, 2019. 1-23.
|
| 16 |
Ge Z, Wang X, Liu H, et al. Boosting adversarial transferability by achieving flat local maxima[C]//Proceedings of the Advances in Neural Information Processing Systems, New York: ACM, 2023. 31766-31781.
|
| 17 |
Xie C H, Zhang Z S, Zhou Y Y, et al. Improving transferability of adversarial examples with input diversity[C]//Proceedings of the 2019 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR). Piscataway: IEEE Press, 2019: 2725-2734.
|
| 18 |
Dong Y P, Pang T Y, Su H, et al. Evading defenses to transferable adversarial examples by translation-invariant attacks[C]//Proceedings of the 2019 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR). Piscataway: IEEE Press, 2019: 4307-4316.
|
| 19 |
Wang X S, He X R, Wang J D, et al. Admix: enhancing the transferability of adversarial attacks[C]//Proceedings of the 2021 IEEE/CVF International Conference on Computer Vision (ICCV). Piscataway: IEEE Press, 2021: 16138-16147.
|
| 20 |
Zhou W, Hou X, Chen Y J, et al. Transferable adversarial perturbations[M]. Computer Vision – ECCV 2018. ChamSpringer International Publishing, 2018: 471-486.
|
| 21 |
Wang Z B, Guo H C, Zhang Z F, et al. Feature importance-aware transferable adversarial attacks[C]//Proceedings of the 2021 IEEE/CVF International Conference on Computer Vision (ICCV) . Piscataway: IEEE Press, 2021: 7619-7628.
|
| 22 |
Zhang J P, Wu W B, Huang J T, et al. Improving adversarial transferability via neuron attribution-based attacks[C]//Proceedings of the 2022 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) . Piscataway: IEEE Press, 2022: 14973-14982.
|
| 23 |
Shafahi A, Najibi M, Ghiasi A, et al. Adversarial training for free![C]//Proceedings of the 33rd International Conference on Neural Information Processing Systems. New York: ACM, 2019: 3358-3369.
|
| 24 |
Tramer F, Kurakin A, Papernot N, et al. Ensemble adversarial training: attacks and defenses [C]//Proceedings of the International Conference on Learning Representations, Vancouver: ICLR, 2018. 1-29.
|
| 25 |
Guo C, Rana M, Cisse M, et al. Countering adversarial images using input transformations[C]//Proceedings of the International Conference on Learning Representations, Vancouver: ICLR, 2018. 1-16.
|
| 26 |
Liao F Z, Liang M, Dong Y P, et al. Defense against adversarial attacks using high-level representation guided denoiser[C]//Proceedings of the 2018 IEEE/CVF Conference on Computer Vision and Pattern Recognition. Piscataway: IEEE Press, 2018: 1778-1787.
|
| 27 |
Xie C, Wang J, Zhang Z, et al. Miti-gating adversarial effects through randomization [C]//Proceedings of the International Conference on Learning Representations, Vancouver: ICLR, 2018.
|
| 28 |
Xu W, Evans D, Qi Y. Feature squeezing: detecting adversarial examples in deep neural networks [C]//Proceedings of the Network and Distributed System Security Symposium, San Diego: Internet Society, 2018. 1-15.
|
| 29 |
Naseer M, Khan S, Hayat M, et al. A self-supervised approach for adversarial robustness[C]//Proceedings of the 2020 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR). Piscataway: IEEE Press, 2020: 259-268.
|
| 30 |
Cohen J, Rosenfeld E, Kolter J Z. Certified adversarial robustness via randomized smoothing [C]//Proceedings of the International Conference on Machine Learning, 2019: 1310-1320.
|
| 31 |
Nie W, Guo B, Huang Y, et al. Diffusion models for adversarial purification [C]//Proceedings of the International Conference on Machine Learning, 2022: 16805-16827.
|
| 32 |
Croce F, Hein M. Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks[C]//Proceedings of the 37th International Conference on Machine Learning. New York: ACM, 2020: 2206-2216.
|
| 33 |
Russakovsky O, Deng J, Su H, et al. ImageNet large scale visual recognition challenge[J]. International Journal of Computer Vision, 2015, 115 (3): 211- 252.
|
| 34 |
He K M, Zhang X Y, Ren S Q, et al. Deep residual learning for image recognition[C]//Proceedings of the 2016 IEEE Conference on Computer Vision and Pattern Recognition (CVPR). Piscataway: IEEE Press, 2016: 770-778.
|
| 35 |
Simonyan K. Very deep convolutional networks for large-scale image recognition [C]//Proceedings of the International Conference on Learning Representations, San Diego: ICLR, 2015. 1-14.
|
| 36 |
Huang G, Liu Z, Van Der M L, et al. Densely connected convolutional networks[C]//Proceedings of the 2017 IEEE Conference on Computer Vision and Pattern Recognition (CVPR). Piscataway: IEEE Press, 2017: 2261-2269.
|
| 37 |
Szegedy C, Vanhoucke V, Ioffe S, et al. Rethinking the inception architecture for computer vision[C]//Proceedings of the 2016 IEEE Conference on Computer Vision and Pattern Recognition (CVPR). Piscataway: IEEE Press, 2016: 2818-2826.
|
| 38 |
Szegedy C, Ioffe S, Vanhoucke V, et al. Inception-v4, inception-ResNet and the impact of residual connections on learning[C]//Proceedings of the AAAI Conference on Artificial Intelligence, San Francisco: AAAI Press, 2017, 31: 4278-4285.
|
| 39 |
Wang J F, Chen Z Y, Jiang K X, et al. Boosting the transferability of adversarial attacks with global momentum initialization[J]. Expert Systems with Applications, 2024, 255, 124757.
|
| 40 |
Gan F Q, Wo Y. Boosting the transferability of adversarial examples through gradient aggregation[J]. IEEE Transactions on Information Forensics and Security, 2025, 20, 5563- 5576.
|
| 41 |
Liu Z H, Liu Q, Liu T, et al. Feature distillation: DNN-oriented JPEG compression against adversarial examples[C]//Proceedings of the 2019 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR). Piscataway: IEEE Press, 2019: 860-868.
|
| 42 |
Selvaraju R R, Cogswell M, Das A, et al. Grad-CAM: visual explanations from deep networks via gradient-based localization[C]//Proceedings of the 2017 IEEE International Conference on Computer Vision (ICCV). Piscataway: IEEE Press, 2017: 618-626.
|
/
| 〈 |
|
〉 |