Skip to content

Author

Yunlong Wang

1 paper indexed here

We haven’t gathered this author’s papers yet. Follow them and we’ll fetch their work.

Not the right person? Other researchers publish under this name.

Aug 2026

ATR-UAP: Enhancing the Transferability of Data-Free Universal Adversarial Perturbation via Adaptive Truncated Ratio Maximization.

Universal adversarial attacks aim to generate a single image-agnostic perturbation, known as Universal Adversarial Perturbation (UAP), that consistently misleads CNN models across diverse inputs, thus serving as an efficient tool for robustness evaluation. Early approaches to universal attacks typically rely on large-scale training data to optimize UAPs. However, in real-world scenarios, access to such data is often restricted due to privacy concerns or deployment constraints. To address this limitation, data-free universal attacks have been proposed to craft UAPs without requiring any real data. Nevertheless, existing data-free methods generally depend on pre-defined CNN layers (e.g., all or shallow layers), lacking adaptive selection mechanisms. This rigidity limits their transferability to unseen black-box models. Thus, in this paper, we propose a novel Adaptive Truncated Ratio Maximization approach for crafting data-free UAPs, referred to as ATR-UAP. Specifically, adaptive layer-wise weight learning is integrated into the ratio maximization framework, with the update direction jointly regulated by exclusive sparsity and prior guidance. Building on this, we further introduce a variance reduction strategy to uniformly smooth CNN activation values, thereby preventing UAP training from being dominated by extreme activations. Finally, we propose a curriculum-guided alternating optimization algorithm that promotes input diversity in data-free attack settings, while efficiently addressing the multivariate optimization challenge. Experimental results on various benchmark datasets consistently validate the superiority of the proposed ATR-UAP over state-of-the-art data-free UAP methods, particularly in cross-model and cross-task transferability. Furthermore, an in-depth evaluation from diverse perspectives confirms the improved generalization and robustness of our generated data-free UAPs.

Di Ming, Peng Ren, Yuanchengzhi Liu et al. · 0 citations