ICASSP 2025accepted0 citations

CA-UAP: Content-Agnostic Universal Adversarial Perturbation for Enhanced Generalization

Rui Lu, Ziqiang He, Jingyang Wen, Xiangui Kang, Z. Jane Wang

Abstract

Deep Neural Networks (DNNs) have been shown vulnerable to universal adversarial perturbation (UAP), which are imperceptible and capable of fooling the target model for most samples. Existing universal attack methods mainly focus on aggregating the gradient obtained from global image features to directly optimize (noise-based) or indirectly generate (generator-based) UAP. However, such methods do not yet consider improving the generalization of UAP from the perspective of making the perturbation irrelevant to image content. We note that minimizing self-similarity is helpful to make the UAP irrelevant to the image content. Therefore, we propose a novel Content-Agnostic UAP (CA-UAP), which combines global image features and local patch features to optimize UAP. Specifically, we introduce a self-similarity loss that encourages minimizing the similarity between adversarial perturbed global images and their randomly cropped local regions, making the UAP agnostic to image content and consequently enhancing UAP generalization. Extensive experiments on the ILSVRC 2012 dataset demonstrate that our proposed method outperforms existing methods in both untargeted and targeted attacks, e.g., improving the average fooling rate from 79.12% (achieved by the state-of-the-art method) to 82.25% in targeted attacks.

BibTeX
@inproceedings{icassp2025_cauapcontentagno,
  title = {CA-UAP: Content-Agnostic Universal Adversarial Perturbation for Enhanced Generalization},
  author = {Rui Lu and Ziqiang He and Jingyang Wen and Xiangui Kang and Z. Jane Wang},
  booktitle = {ICASSP 2025},
  year = {2025}
}
CA-UAP: Content-Agnostic Universal Adversarial Perturbation for Enhanced Generalization · ICASSP 2025