Two Heads Are Better Than One: Averaging along Fine-Tuning to Improve Targeted Transferability
Hui Zeng, Sanshuai Cui, Biwei Chen, Anjie Peng

TL;DR
This paper introduces a trajectory averaging method during fine-tuning of adversarial examples to enhance their targeted transferability, outperforming existing schemes across various attack scenarios.
Contribution
The paper proposes a novel averaging technique over the fine-tuning trajectory to improve targeted transferability of adversarial examples, addressing limitations of endpoint-only methods.
Findings
Averaging over fine-tuning trajectories improves targeted transferability.
The proposed method outperforms existing fine-tuning schemes.
Experimental results confirm the effectiveness across multiple attack scenarios.
Abstract
With much longer optimization time than that of untargeted attacks notwithstanding, the transferability of targeted attacks is still far from satisfactory. Recent studies reveal that fine-tuning an existing adversarial example (AE) in feature space can efficiently boost its targeted transferability. However, existing fine-tuning schemes only utilize the endpoint and ignore the valuable information in the fine-tuning trajectory. Noting that the vanilla fine-tuning trajectory tends to oscillate around the periphery of a flat region of the loss surface, we propose averaging over the fine-tuning trajectory to pull the crafted AE towards a more centered region. We compare the proposed method with existing fine-tuning schemes by integrating them with state-of-the-art targeted attacks in various attacking scenarios. Experimental results uphold the superiority of the proposed method in boosting…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Code & Models
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsMuscle activation and electromyography studies · Assistive Technology in Communication and Mobility
MethodsSeventeen Ways to Call Uphold Helpline Full Guide USA 24 Hour Assistance · Autoencoders
