Skip to content

CITP: Cross-instance targeted perturbations.

Aug 2026 · Neural Networks · Vol 205 Pt B, pp. 109499 · 0 citations · 42 references
Medicine

TL;DR

A generative adversarial framework named CITP for generating cross-instance targeted perturbations that leverages shared features among instances of the same class to produce perturbations that can be transferred to other instances within that class.

Abstract

Universal Adversarial Perturbations (UAPs) differ from traditional image-specific perturbations in that they deceive target models across diverse instances using a single perturbation. Prior research has primarily focused on enhancing the transferability of non-targeted UAPs; however, these efforts fail to generate transferable UAPs capable of classifying images into a specific target class. To address this limitation, we propose a generative adversarial framework named CITP for generating cross-instance targeted perturbations. CITP leverages shared features among instances of the same class to produce perturbations that can be transferred to other instances within that class. The framework distinguishes between generated adversarial samples and images of the target class, enabling it to learn the label distribution of the target class. Additionally, CITP integrates a mid-level feature discriminator to improve the transferability of perturbations across different model architectures. Experimental results demonstrate that CITP exhibits exceptional transferability in cross-instance targeted attacks and achieves strong performance against four defense mechanisms. Notably, CITP extends beyond image data, enabling precise targeted attacks on video data as well.

View source

Similar papers

#artificial intelligence Preprint Sep 2026

What Makes Adversarial Examples Transfer Across Deepfake Detectors?

A controlled evaluation of adversarial transferability across 60 detectors spanning six backbones, two pretraining regimes, and five training-data configurations establishes source-model selection as central dimensions of credible transfer-based black-box robustness evaluation.

Rafael M. Mamede, Pedro C. Neto, A. F. Sequeira · 0 citations
Sep 2026

Seeing Through Threats: Adversarial Detection Through Explainability (ADEx)

Deep Neural Networks (DNNs) remain vulnerable to adversarial perturbations, raising significant concerns in image processing applications, particularly in high-stakes domains such as medical imaging and security-critical systems. Most existing defense strategies are limited by domain specificity, architectural dependen...

Syamantak Sarkar, Nirmal Joseph, Sudhish N. George et al. · 0 citations
#machine learning Preprint Sep 2026

One Attack to Fool Them All: Highly Transferable Black-Box Adversarial Attacks on Frontier MLLMs

Adversarial attacks have long posed a fundamental threat to machine learning systems. As multimodal large language models (MLLMs) rapidly evolve and become widely deployed, assessing their vulnerability to such attacks is essential for their safe use. In this work, we investigate whether a single adversarial image can...

Sen Nie, Jie Zhang, Zhong Ling Wang et al. · 0 citations
Sep 2026

Towards Transferable Black-Box Attack via Minimizing Maximum Model Discrepancy.

Adversarial attacks on black-box models, which operate without direct access to the target system, present a significant challenge due to the lack of a foundational theory for the transferability of adversarial examples. This paper introduces a paradigm shift in black-box adversarial attacks by minimizing model discrep...

An-Qi Zhao, Tong Chu, Ya-Hao Liu et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.