Pareto-Improving Adversarial Attacks with Primal-Dual Regularization

šŸ“… 2026-10-03
šŸ“ˆ Citations: 0
✨ Influential: 0
šŸ“„ PDF
šŸ¤– AI Summary
This study addresses the spurious trade-off between transferability and imperceptibility in adversarial attacks under a fixed perturbation budget. We propose ST, a plug-and-play primal-dual wrapper that performs two-step optimization updates grounded in Fenchel duality theory. By incorporating Lāˆž saturation regularization, ST transcends conventional perceptual priors and reveals the latent advantages of highly transferable attacks while enhancing stealthiness, all without requiring auxiliary models. Experimental results demonstrate that ST effectively expands the Pareto frontier, achieving synergistic optimization of transferability and imperceptibility. Specifically, it maintains or improves attack success rates while yielding 17% and 14% improvements in LPIPS and NIQE metrics, respectively.
šŸ“ Abstract
Transferable adversarial attacks are arguably the most practical black-box threat model. Under the same perturbation budget, stronger transfer attacks attain higher attack success rate (ASR), yet their imperceptibility also tends to degrade. Under such a fixed-budget protocol, transferability and imperceptibility therefore appear to trade off against each other. We argue that this conflict is an artifact of fixed-budget evaluation, not an intrinsic trade-off. When attacks are compared on the ASR--imperceptibility Pareto frontier obtained by sweeping $\epsilon$, stronger transfer attacks already attain better imperceptibility at matched ASR than weaker ones. To exploit this latent advantage, we introduce the stealthy transfer attack ST, a plug-in primal-dual wrapper that adds an $L_\infty$ saturation regularizer to the standard constrained objective and resolves it through a two-step primal-dual update: a projected primal step on the perturbation coupled with an $L_1$-ball projection on a dual variable that absorbs the regularizer through Fenchel duality, requiring no auxiliary models or handcrafted perceptual priors. Empirically, ST extends the Pareto frontier across different base attacks and additional surrogate architectures. At $\epsilon{=}16/255$, average imperceptibility gains over each base attack are $17\%$ on LPIPS and $14\%$ on NIQE while ASR is preserved or improved. At matched high-ASR levels, the strongest ST variants further Pareto-dominate dedicated stealth-oriented transfer attacks, confirming that the latent imperceptibility advantage of strong transfer attacks can be unlocked by a primal-dual optimization wrapper without sacrificing transferability. Code will be made available at \url{https://github.com/AndssY/ST}.
Problem

Research questions and friction points this paper is trying to address.

transferable adversarial attacks
imperceptibility
Pareto frontier
fixed-budget evaluation
Innovation

Methods, ideas, or system contributions that make the work stand out.

Transferable adversarial attacks
Primal-dual regularization
Pareto frontier
Stealthy transfer attack
Fenchel duality
Yang Dai
Yang Dai
Shenzhen Institutes of Advanced Technology,Chinese Academy of Sciences
perovskitesmemristor
L
Longfei Zhang
Laboratory for Big Data and Decision, National University of Defense Technology, Changsha 410073, China
Wei Tao
Wei Tao
Huazhong University of Science and Technology
QuantizationLLMTime-Series
L
Li Shen
School of Cyber Science and Technology, Shenzhen Campus of Sun Yat-sen University, Shenzhen 518107, China
J
Jincai Huang
Laboratory for Big Data and Decision, National University of Defense Technology, Changsha 410073, China
Q
Qing Tao
Hefei Institute of Technology, Hefei 230009, China