Can Adaptive Gradient Transport Fool Deep Models?
Riya Goyal ⋅ JOY DHAR ⋅ Puneet Goyal
Abstract
Small adversarial perturbations can alter deep neural network predictions, making reliable white-box attacks (e.g., PGD, FAB, AutoAttack, DiffAttack, and RisingAttack) important for evaluating model vulnerability. This raises a complementary question: *can spatial gradient propagation itself adapt as the attack evolves?* To explore this, we introduce **Multi-scale Adaptive Screened Transport Attack (MASTA)**, a white-box attack that propagates adversarial gradient information across image regions through state-adaptive multi-scale screened transport. MASTA treats the attack gradient as a spatial signal and propagates it across image regions through multi-scale screened transport. At iteration $t$, the normalized gradient is accumulated into a charge field $q_t$, which is propagated at multiple screening scales indexed by $k$. The transport and adversarial update are: $$(I-s_k\Delta)\phi_t^{(k)}=q_t,\qquad x_{t+1}=\Pi_{\mathcal{B}_{\infty}(x_0,\epsilon)} (x_t+\alpha_t\sigma_t\odot\mathrm{sign}(D_t))$$ Here, $x_0$ is the clean image, $x_t$ the current adversarial image, $\alpha_t$ the step size, $s_k$ the screening scale, $\phi_t^{(k)}$ the potential field, $D_t$ the drive field, and $\sigma_t$ the adaptive conductivity controlling the contribution of transported gradients to each update. After the iterative updates, the final adversarial example $x^\ast$ is selected from the generated candidates using the highest attack margin while satisfying $\|x^\ast-x_0\|_\infty\leq\epsilon$. We evaluate MASTA across six natural and medical imaging benchmarks: CIFAR-10/100, ImageNet-1K, BUSI, BUS-BRA, and UDIAT, using diverse CNN and transformer architectures, including ResNet-50, ViT, and DINO-ViT. At $\epsilon=8/255$, MASTA achieves up to **98.97% Attack Success Rate (ASR)**, surpassing PGD, FAB, AutoAttack, DiffAttack, and RisingAttack by up to **61.54 percentage points**. These results show strong attack effectiveness across architectures and imaging domains, suggesting adaptive spatial-gradient transport during optimization as a promising direction for constructing white-box attacks.
Chat is not available.
Successful Page Load