| 注册
首页|期刊导航|西安电子科技大学学报(自然科学版)|基于ViT的高迁移性黑盒对抗样本生成

基于ViT的高迁移性黑盒对抗样本生成

康行铠 刘洪毅 周慧鹏 王亚杰 祝烈煌

西安电子科技大学学报(自然科学版)2026,Vol.53Issue(3):120-134,15.
西安电子科技大学学报(自然科学版)2026,Vol.53Issue(3):120-134,15.DOI:10.19665/j.issn1001-2400.20260402

基于ViT的高迁移性黑盒对抗样本生成

High-transferability adversarial example generation for the black-box vision transformer

康行铠 1刘洪毅 1周慧鹏 2王亚杰 2祝烈煌2

作者信息

  • 1. 北京理工大学 网络空间安全学院,北京 100081||山东省能源工业互联网大数据技术重点实验室,山东 济南 250003
  • 2. 北京理工大学 网络空间安全学院,北京 100081
  • 折叠

摘要

Abstract

Transfer-based adversarial attacks against convolutional neural networks(CNNs)exploit the observation that models trained on the same task often share similar decision boundaries,crafting examples on a substitute model that transfer to a target.However,due to architectural differences,existing methods struggle to achieve cross-architecture transfer.To address this,we propose the OptiEncode,a Vision Transformer(ViT)‒based method for generating high-transferability black-box adversarial examples.Leverag-ing ViT's strong capability to localize salient features,OptiEncode uses Grad-CAM to identify cross-architecture consensus regions and Sobel to extract architecture-agnostic high-frequency structures,and then injects perturbations only on their intersection to enhance transferability.Unlike SE,PNA,and FPR,which primarily modify the model internals,the OptiEncode explicitly aligns cross-architecture shared features in the input space,thus making it orthogonal and stackable with those approaches.Evaluations on black-box targets across diverse architectures(ViT,CNN,and MLP)show that the OptiEncode improves ViT-to-ViT transfer by about 10%on average and achieves up to 15%gains in cross-architecture settings(e.g.,ViT→CNN).These results indicate that explicitly aligning the"consensus regions ∩ high-frequency structures"in the input space effectively narrows the cross-architecture transfer gap and offers a reusable,complementary path for improving the practicality of black-box transfer attacks.

关键词

对抗样本/迁移性/黑盒攻击/深度学习

Key words

adversarial example/transferability/black-box attacks/deep learning

分类

信息技术与安全科学

引用本文复制引用

康行铠,刘洪毅,周慧鹏,王亚杰,祝烈煌..基于ViT的高迁移性黑盒对抗样本生成[J].西安电子科技大学学报(自然科学版),2026,53(3):120-134,15.

基金项目

云南省科技计划项目云南省大数据技术及应用创新中心资助(202605AK340003) (202605AK340003)

云南省重大科技专项计划(202502AD080008) (202502AD080008)

云南省新型研发机构培育对象项目(202404BQ040148) (202404BQ040148)

西安电子科技大学学报(自然科学版)

1001-2400

访问量0
|
下载量0
段落导航相关论文