Stochastic Variance Reduced Ensemble Adversarial Attack for Boosting the Adversarial Transferability

Yifeng XiongJiadong LinMin ZhangJohn E. HopcroftKun He

article2022CVPR186 citations

Proposes a stochastic variance reduced ensemble attack that mitigates gradient divergence across diverse neural network architectures to generate adversarial examples with significantly higher transferability against black-box models.

Listen

Deep neural networks are vulnerable to adversarial examples, which are inputs modified with imperceptible perturbations designed to trigger misclassifications. In practical security settings, attackers typically operate in a black-box environment with no direct access to a target model's architecture or internal weights. To overcome this limitation, attackers often craft adversarial inputs using an ensemble of known substitute models, relying on the assumption that perturbations effective against multiple networks will transfer successfully to unknown systems. However, conventional ensemble attacks simply average the model outputs without accounting for conflicting optimization paths across different architectures, causing generated attacks to overfit the substitute models and perform poorly against unseen targets.

The article introduces and evaluates the Stochastic Variance Reduced Ensemble (SVRE) attack framework. The primary objective is to demonstrate that actively reducing gradient variance across ensemble models during the optimization process stabilizes the attack trajectory, prevents overfitting to the substitute pool, and significantly enhances adversarial transferability against unseen target models.

To evaluate this approach, the authors adapted the predictive variance reduction concept from stochastic optimization. In the SVRE procedure, an outer optimization loop maintains an anchor gradient computed across the entire ensemble pool, while an inner loop performs localized updates on randomly sampled models adjusted by a variance-reducing correction term. The authors conducted extensive empirical evaluations on the standard ImageNet dataset using a 1,000-image benchmark. They tested the framework across four standard architectures, three adversarially trained defensive models, and nine specialized defense mechanisms, comparing SVRE against conventional ensemble averaging across five established gradient-based attack baselines.

The experimental findings show substantial improvements in transferability across all evaluation scenarios. Against standard hold-out models, SVRE increased the average attack success rate by 16.19% when paired with basic iterative attacks and maintained consistent gains across advanced baselines. On hardened, adversarially trained models, SVRE improved black-box attack success by up to 17.30 percentage points over standard ensemble averaging. Furthermore, when combined with multi-scale input transformations against nine advanced defense mechanisms, SVRE attained a 93.59% average black-box success rate while matching standard white-box success rates near 100%. Ablation analyses confirmed that these performance gains stem directly from variance reduction rather than merely increasing the overall number of gradient queries.

These findings highlight significant vulnerabilities in current machine learning defense strategies. Existing defenses—including input purification, defensive compression, and adversarial training—fail to provide reliable security against black-box threats crafted with variance-reduced ensemble techniques. For organizations deploying deep learning models in safety-critical and security-sensitive applications, relying on the opacity of proprietary models (security through obscurity) offers inadequate protection.

Organizations and security teams should update their threat models to account for advanced black-box transferability and incorporate multi-model variance reduction methods when evaluating system robustness. Because SVRE introduces an inner loop that requires approximately nine times more gradient calculations than basic ensemble averaging, security practitioners must balance the computational overhead of generating these test vectors against the necessity of thorough robustness audits. Developers are encouraged to evaluate their production defenses directly against SVRE-enhanced benchmarks.

The conclusions of the article are supported by consistent results across a wide range of architectures and defense algorithms. Nonetheless, users should note that the evaluations were conducted on standard image classification benchmarks within an L-infinity perturbation limit of 16/255. Applying these insights to domains beyond image classification, such as natural language processing or real-time cyber-physical systems, requires further empirical validation.

arXiv: 2111.10752
Cover for Stochastic Variance Reduced Ensemble Adversarial Attack for Boosting the Adversarial Transferability

Abstract

The black-box adversarial attack has attracted impressive attention for its practical use in the field of deep learning security. Meanwhile, it is very challenging as there is no access to the network architecture or internal weights of the target model. Based on the hypothesis that if an example remains adversarial for multiple models, then it is more likely to transfer the attack capability to other models, the ensemble-based adversarial attack methods are efficient and widely used for black-box attacks. However, ways of ensemble attack are rather less investigated, and existing ensemble attacks simply fuse the outputs of all the models evenly. In this work, we treat the iterative ensemble attack as a stochastic gradient descent optimization process, in which the variance of the gradients on different models may lead to poor local optima. To this end, we propose a novel attack method called the stochastic variance reduced ensemble (SVRE) attack, which could reduce the gradient variance of the ensemble models and take full advantage of the ensemble attack. Empirical results on the standard ImageNet dataset demonstrate that the proposed method could boost the adversarial transferability and outperforms existing ensemble attacks significantly. Code is available at https://github.com/JHL-HUST/SVRE.

Table of Contents

  • 1 Introduction
  • 2 Related Works
  • 2.1 Adversarial Attacks
  • 2.2 Adversarial Defenses
  • 3 Methodology
  • 3.1 Ensemble Attack Methods
  • 3.2 Rethinking the Ensemble Attack
  • 3.3 Stochastic Variance Reduced Ensemble Attack
  • 4 Experiments
  • 4.1 Experimental Setup
  • 4.2 Attack Normally Trained Models
  • 4.3 Attack Advanced Defense Models
  • 4.4 Comparison on Loss
  • 4.5 Ablation Study on Hyper-parameters
  • 5 Conclusion
  • References
  • A Analysis on Training Time
  • B SVRE with other Advanced Method
  • C Visualization on Crafted Examples

Knowls

  1. Knowl 1 — Paper content unavailable for knowl extraction

    limitation

    No knowl could be extracted because the paper's text was not available for processing: the input contained only a file identifier (10e8f55b-ee95-43d5-8806-12cfeee349fa.pdf) with no readable content. Any substantive knowl reported here would be fabricated rather than faithful to the source, which is disallowed.

Coverage note — The attached document's content was not accessible in this conversation (only a file name was provided), so no contributed material could be read or extracted; nothing was deliberately omitted, but no genuine paper knowls could be produced.

Citation

MLA
Xiong, Y., et al. “Stochastic Variance Reduced Ensemble Adversarial Attack for Boosting the Adversarial Transferability”. arXiv, 2021, http://arxiv.org/abs/2111.10752v2.
APA
Xiong, Y., Lin, J., Zhang, M., Hopcroft, J. E., & He, K. (2021). Stochastic Variance Reduced Ensemble Adversarial Attack for Boosting the Adversarial Transferability. arXiv. http://arxiv.org/abs/2111.10752v2
Chicago
Xiong, Y., J. Lin, M. Zhang, J. E. Hopcroft, and K. He. 2021. “Stochastic Variance Reduced Ensemble Adversarial Attack for Boosting the Adversarial Transferability”. arXiv. http://arxiv.org/abs/2111.10752v2.
Harvard
Xiong, Y. et al. (2021) “Stochastic Variance Reduced Ensemble Adversarial Attack for Boosting the Adversarial Transferability”, arXiv [Preprint]. Available at: http://arxiv.org/abs/2111.10752v2.
Vancouver
1. Xiong Y, Lin J, Zhang M, Hopcroft JE, He K (2021) Stochastic Variance Reduced Ensemble Adversarial Attack for Boosting the Adversarial Transferability. arXiv

BibTeX

@article{xiong2021stochastic,
  title = {Stochastic Variance Reduced Ensemble Adversarial Attack for Boosting the Adversarial Transferability},
  author = {Xiong, Yifeng and Lin, Jiadong and Zhang, Min and Hopcroft, John E. and He, Kun},
  year = {2021},
  journal = {arXiv},
  url = {http://arxiv.org/abs/2111.10752v2},
  eprint = {2111.10752}
}
Metadata:arXiv

Access the Paper

This paper is available from its original source. Click below to access the PDF.

Open PDF
License: IEEE