Skip to main navigation Skip to search Skip to main content

Exploiting feature-rich image locations for adversarial attacks on image classifiers without network access

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

Physical adversarial attacks have advanced rapidly, with numerous methods developed to overcome the challenge of applying perturbations in real-world settings. However, less attention has been given to the challenge of information access. Most adversarial attacks operate in white-box settings or information-constrained black-box scenarios. Although prior work has explored universal adversarial examples and attacks without direct access to target networks, existing literature does not support the broad application of pre-existing adversarial methods in what we introduce as the “box-agnostic scenario”. Unlike the black-box setting, which assumes access to both inputs and outputs of the target network, the box-agnostic scenario assumes knowledge only of the input image, with no access to classification outputs. To address this challenge, we introduce Multi-Targeted Gradient Training (MTGT), a novel approach that leverages encoder-decoder architectures trained on the combined gradients of multiple pretrained classifiers. By incorporating diverse architectures, MTGT captures a wide range of feature detectors, allowing feature-rich regions to emerge naturally during training. Additionally, we introduce a novel order-based loss function that optimizes training by emphasizing the most salient pixels in the combined gradients, guiding the network to focus on features most critical to successful attacks. This process enables the network to identify and exploit high-information areas within an image, facilitating adversarial attacks that target these regions rather than relying on any single network’s gradients. We evaluate MTGT’s effectiveness by testing its adversarial capabilities against networks outside the set used during training, demonstrating its potential for generating attacks that generalize across unseen architectures.

Original languageEnglish (US)
Title of host publicationEmerging Topics in Artificial Intelligence, ETAI 2025
EditorsGiovanni Volpe, Joana B. Pereira, Daniel Brunner, Aydogan Ozcan
PublisherSPIE
ISBN (Electronic)9781510690783
DOIs
StatePublished - Sep 17 2025
EventEmerging Topics in Artificial Intelligence, ETAI 2025 - San Diego, United States
Duration: Aug 3 2025Aug 7 2025

Publication series

NameProceedings of SPIE - The International Society for Optical Engineering
Volume13585
ISSN (Print)0277-786X
ISSN (Electronic)1996-756X

Conference

ConferenceEmerging Topics in Artificial Intelligence, ETAI 2025
Country/TerritoryUnited States
CitySan Diego
Period8/3/258/7/25

All Science Journal Classification (ASJC) codes

  • Electronic, Optical and Magnetic Materials
  • Instrumentation
  • Condensed Matter Physics
  • Computer Science Applications
  • Applied Mathematics
  • Electrical and Electronic Engineering

Fingerprint

Dive into the research topics of 'Exploiting feature-rich image locations for adversarial attacks on image classifiers without network access'. Together they form a unique fingerprint.

Cite this