Aug 2026· Neural Networks· Vol 205 Pt B, pp.
109535
· 0 citations· 61 references
Medicine
TL;DR
Empirical support is provided for the utility of structure-aware perturbation refinement in improving black-box adversarial transferability across heterogeneous visual architectures.
Abstract
Transfer-based black-box adversarial attacks provide a practical means to evaluate the robustness of deep neural networks under restricted access to target models. However, existing approaches suffer from severe performance degradation in cross-architecture scenarios, particularly when adversarial examples crafted on Vision Transformers (ViTs) are transferred to convolutional neural networks (CNNs). We argue that this limitation cannot be fully attributed to optimization strategies alone, but may also be related to the mismatch between perturbation structure and model-specific inductive biases. To address this issue, we propose a structure-aware adversarial perturbation refinement framework that explicitly enforces spatial coherence during forward propagation. The proposed method consists of three components. First, spatial autocorrelation analysis is used to guide perturbation allocation toward structurally discriminative regions. Second, spatially connected perturbation patterns are introduced to help preserve perturbation effects under convolutional smoothing and pooling operations. Third, the perturbation strength is adaptively adjusted across network depth to balance structural disruption and semantic preservation. Extensive experiments on the ImageNet benchmark show that the proposed approach achieves competitive and often stronger performance than the compared transfer-based attacks across diverse ViT and CNN architectures, with particularly notable gains in the challenging ViT-to-CNN transfer setting. These results provide empirical support for the utility of structure-aware perturbation refinement in improving black-box adversarial transferability across heterogeneous visual architectures.
Transfer-Dislocation and Curvature-Aware Gradient (TD-CAG), a new adversarial attack framework comprising two complementary modules: a curvature-aware gradient (CAG) module for modeling local nonlinearity, and a translation-dislocation (TD) module for modeling saliency misalignment.
Hailing Kuang, Chen Wan, Xiaohai Lu et al.· Neural Networks· 0 citations
FDT-PC (Frequency Domain Transformation with Perceptual Constraints), a novel method that enhances adversarial transferability across different model architectures, is proposed, which achieves superior black-box attack performance on both CNNs and Vision Transformers, outperforming existing state-of-the-art input transformation methods.
Bo Li, Li Tang, Xin Jin et al.· ACM Transactions on Multimed...· 0 citations
Transfer-based black-box attacks are an important tool for evaluating deployed vision models, yet adversarial examples generated from Vision Transformer (ViT) surrogates often exhibit limited cross-architecture transferability. Existing momentum-based attacks are effective for convolutional neural network (CNN) surrogates, but they can accumulate stale directions and overfit the surrogate when the source model is a ViT. This paper presents Ada-MGNS, a ViToriented transferable attack that combines adaptive momentum with deep attention guidance. The adaptive component measures the directional discrepancy between the current guided gradient and the accumulated trajectory, and then attenuates stale momentum when the search direction becomes unstable. The guidance component fuses the classification gradient with an auxiliary gradient extracted from the last transformer block’s attention responses, encouraging perturbations to disturb both output decisions and semantic aggregation. Experiments on ImageNet with four ViT surrogates, thirteen standard black-box targets, and five defense models show that Ada-MGNS consistently improves attack success rates over representative ViT-specific baselines, remains compatible with DI/TI transformations and effective against adversarially trained and purification-based defenses.
Lei Lu, Run-Han Yao, Qinghe Du et al.· 2026 International Conferenc...· 0 citations
Season, a spectrum-aware orthogonal gradient refinement framework for L-infinity transfer attacks against black-box target models on ImageNet, using a white-box surrogate to improve transfer success rate.
The study concluded that adversarial resilience is largely determined by the interaction between model architecture and defense strategy, highlighting the need for architecture-specific defense selection when developing secure medical image classification systems.
Y. Heryadi, I. Sonata, Bambang Krismono Triwijoyo· Matrik· 0 citations
Adversarial examples generated on a surrogate deep neural network (DNN) can often successfully fool other black-box DNN models. This cross-model transferability poses serious security threats to DNNs in practical applications. Input transformation techniques are widely used to enhance adversarial transferability by increasing the diversity of input images. However, existing methods primarily rely on local operations with limited degrees of freedom (DOF), such as block-wise shuffling and resizing, overlooking global perspective transformations that naturally arise from viewpoint changes. In this work, we propose a Perspective-Invariant Attack (PIA), which introduces a multi-DOF vertex sampling strategy that systematically covers the perspective transformation hierarchy from 2-DOF translation to 8-DOF projective mapping. By generating geometrically diverse input variations, PIA effectively reduces overfitting of adversarial perturbations to the surrogate model, thereby improving adversarial transferability. We further propose PIA-Mix, a generic extension that maintains a complementary transformation pool and efficiently combines our perspective transformation with auxiliary methods for improved transferability. Extensive experiments involving various DNN architectures, advanced defense mechanisms, and multimodal large language models (LLMs) demonstrate that PIA and PIA-Mix outperform state-of-the-art transfer-based attacks.
Kaisheng Liang, Yiming Cao, Bin Xiao· IEEE Transactions on Informa...· 0 citations