A Method of Enhancing Adversarial Example Transferability Based on NadaMax Update and Dynamic Regularization
SONG Yafei
QIU Wenbo
WANG Yifei
FENG Cunqian
Abstract:To address the problem of insufficient transferability of adversarial examples and inadequate black-box attack capabilities in deep learning models,this study designs an iterative fast gradient method based on the NadaMax optimizer(NM-FGSM).This method integrates the advantages of Nesterov Accel-erated Gradient and the Adamax optimizer,improving the accuracy of gradient updates through adaptive learning rates and lookahead momentum vectors.Additionally,dynamic regularization is introduced to en-hance the convexity of the problem,optimizing algorithm stability and specificity.The experimental re-sults demonstrate that the NM-FGSM is prior to the existing methods under conditions of various attack strategies,particularly in advanced defense scenarios,attack success rate increases by 4%~8%.The dy-namically regularized loss function enhances the cross-model transferability of adversarial examples,there-by further improving black-box attack effectiveness.Finally,points out the way forward for the NM-FGSM algorithm and defense measures,providing a new insight into the security research of deep learning models.
Keywords:transferabilityblack-box attackNadaMax optimizermomentumadaptive learning ratedy-namic regularization
Publication Date:2025-06-25
Online Publishing Date:2025-08-15(First online date of this platform, not the publication date of the document)
Pages:9( 119-127 )
