IGAff: Benchmarking Adversarial Iterative and Genetic Affine Algorithms on Deep Neural Networks

📅 2025-09-08
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
Evaluating adversarial robustness of deep neural networks (e.g., ResNet-18, DenseNet-121, Swin Transformer V2, ViT) under black-box settings remains challenging due to limited model access and gradient inaccessibility. To address this, we propose two novel black-box attack algorithms: Affine Transformation Attack (ATA) and Affine Genetic Attack (AGA). Both methods synergistically integrate randomized affine transformations, genetic optimization, noise perturbations, and a dedicated attack scoring function to efficiently generate adversarial examples under both untargeted and targeted attack settings. Extensive evaluation across Tiny ImageNet, Caltech-256, and Food-101 demonstrates that our approaches significantly improve attack success rates—by up to 8.82%—outperforming state-of-the-art black-box attacks. Moreover, they exhibit strong cross-architecture generalization and enable verifiable robustness assessment. This work establishes a new paradigm for systematic vulnerability analysis and defense-oriented evaluation of vision models in realistic black-box scenarios.

Technology Category

Computer Vision: Adversarial Attacks & RobustnessMachine Learning: Adversarial Learning & RobustnessMultiagent Systems: Adversarial Agents

Application Category

User Modeling, Personalization and Recommendation: Attacks and countermeasures in recommendation systemsResponsible Web: Algorithmic accountability and transparency on the webSearch and Retrieval-Augmented AI: Agentic search
📝 Abstract
Deep neural networks currently dominate many fields of the artificial intelligence landscape, achieving state-of-the-art results on numerous tasks while remaining hard to understand and exhibiting surprising weaknesses. An active area of research focuses on adversarial attacks, which aim to generate inputs that uncover these weaknesses. However, this proves challenging, especially in the black-box scenario where model details are inaccessible. This paper explores in detail the impact of such adversarial algorithms on ResNet-18, DenseNet-121, Swin Transformer V2, and Vision Transformer network architectures. Leveraging the Tiny ImageNet, Caltech-256, and Food-101 datasets, we benchmark two novel black-box iterative adversarial algorithms based on affine transformations and genetic algorithms: 1) Affine Transformation Attack (ATA), an iterative algorithm maximizing our attack score function using random affine transformations, and 2) Affine Genetic Attack (AGA), a genetic algorithm that involves random noise and affine transformations. We evaluate the performance of the models in the algorithm parameter variation, data augmentation, and global and targeted attack configurations. We also compare our algorithms with two black-box adversarial algorithms, Pixle and Square Attack. Our experiments yield better results on the image classification task than similar methods in the literature, achieving an accuracy improvement of up to 8.82%. We provide noteworthy insights into successful adversarial defenses and attacks at both global and targeted levels, and demonstrate adversarial robustness through algorithm parameter variation.
Problem

Research questions and friction points this paper is trying to address.

Benchmarking adversarial attacks on deep neural networks
Evaluating black-box iterative and genetic affine algorithms
Assessing model robustness against global and targeted attacks
Innovation

Methods, ideas, or system contributions that make the work stand out.

Novel black-box iterative adversarial algorithms
Affine Transformation Attack maximizing attack score
Affine Genetic Attack combining noise and transformations
🔎 Similar Papers
No similar papers found.
S
Sebastian-Vasile Echim
Faculty of Automatic Control and Computers, National University of Science and Technology POLITEHNICA Bucharest, Bucharest, Romania
A
Andrei-Alexandru Preda
Faculty of Automatic Control and Computers, National University of Science and Technology POLITEHNICA Bucharest, Bucharest, Romania
Dumitru-Clementin Cercel
Dumitru-Clementin Cercel
Teaching Assistant of Computer Science, University Politehnica of Bucharest
Social Network AnalysisNatural Language ProcessingInformation RetrievalMachine Learning
F
Florin Pop
National Institute for Research & Development in Informatics - ICI Bucharest, Bucharest, Romania