{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/frequency-domain-model-augmentation-for","title":"Frequency Domain Model Augmentation for Adversarial Attack","arxiv_id":"2207.05382","date":"2022-07-12","proceeding":null,"authors":["Yuyang Long","Qilong Zhang","Boheng Zeng","Lianli Gao","Xianglong Liu","Jian Zhang","Jingkuan Song"],"abstract":"For black-box attacks, the gap between the substitute model and the victim model is usually large, which manifests as a weak attack performance. Motivated by the observation that the transferability of adversarial examples can be improved by attacking diverse models simultaneously, model augmentation methods which simulate different models by using transformed images are proposed. However, existing transformations for spatial domain do not translate to significantly diverse augmented models. To tackle this issue, we propose a novel spectrum simulation attack to craft more transferable adversarial examples against both normally trained and defense models. Specifically, we apply a spectrum transformation to the input and thus perform the model augmentation in the frequency domain. We theoretically prove that the transformation derived from frequency domain leads to a diverse spectrum saliency map, an indicator we proposed to reflect the diversity of substitute models. Notably, our method can be generally combined with existing attacks. Extensive experiments on the ImageNet dataset demonstrate the effectiveness of our method, \\textit{e.g.}, attacking nine state-of-the-art defense models with an average success rate of \\textbf{95.4\\%}. Our code is available in \\url{https://github.com/yuyang-long/SSA}.","url_abs":"https://arxiv.org/abs/2207.05382v1","url_pdf":"https://arxiv.org/pdf/2207.05382v1.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"frequency-domain-model-augmentation-for","repo_url":"https://github.com/yuyang-long/ssa","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":1,"framework":"pytorch","reach":{"status":"ok","spdx":"Apache-2.0"}},{"paper_slug":"frequency-domain-model-augmentation-for","repo_url":"https://github.com/Trustworthy-AI-Group/TransferAttack","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"pytorch","reach":null}],"tasks":[{"task_slug":"adversarial-attack","task_name":"Adversarial Attack"},{"task_slug":"diversity","task_name":"Diversity"},{"task_slug":"model","task_name":"model"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":null,"atlas_url":"https://app.syntology.ai/?focus=2207.05382","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2207.05382"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-24T18:15:14+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/Trustworthy-AI-Group/TransferAttack","reach":null},{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/yuyang-long/ssa","reach":{"status":"ok","spdx":"Apache-2.0"}},{"provenance":"deterministic:regex_extraction","url":"https://github.com/yuyang-long/SSA","reach":{"status":"ok","spdx":"Apache-2.0"}}],"summary":{"ran":2,"unverified":3},"by_repo_kind":{"official":{"samples":1,"ran":0,"repositories":1},"listed":{"samples":4,"ran":2,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":0,"samples":[{"code_sha256_prefix":"ec2bee7d91dd60b8","entry":"LogitLoss","repo":"Trustworthy-AI-Group/TransferAttack","repo_kind":"listed","path":"transferattack/advanced_objective/fft.py","file_url":"https://github.com/Trustworthy-AI-Group/TransferAttack/blob/HEAD/transferattack/advanced_objective/fft.py","link_basis":"first_harvest_node","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"ec2bee7d91dd60b8"}},{"code_sha256_prefix":"590dffccb915a437","entry":"Logit_marginLoss","repo":"Trustworthy-AI-Group/TransferAttack","repo_kind":"listed","path":"transferattack/advanced_objective/fft.py","file_url":"https://github.com/Trustworthy-AI-Group/TransferAttack/blob/HEAD/transferattack/advanced_objective/fft.py","link_basis":"first_harvest_node","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"590dffccb915a437"}},{"code_sha256_prefix":"02ff74745f5de1ce","entry":"FFT","repo":"Trustworthy-AI-Group/TransferAttack","repo_kind":"listed","path":"transferattack/advanced_objective/fft.py","file_url":"https://github.com/Trustworthy-AI-Group/TransferAttack/blob/HEAD/transferattack/advanced_objective/fft.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"02ff74745f5de1ce"}},{"code_sha256_prefix":"dc12835f41a53f69","entry":"SU","repo":"Trustworthy-AI-Group/TransferAttack","repo_kind":"listed","path":"transferattack/advanced_objective/fft.py","file_url":"https://github.com/Trustworthy-AI-Group/TransferAttack/blob/HEAD/transferattack/advanced_objective/fft.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"dc12835f41a53f69"}},{"code_sha256_prefix":"56375b8dd939849e","entry":"Spectrum_Simulation_Attack","repo":"yuyang-long/SSA","repo_kind":"official","path":"attack.py","file_url":"https://github.com/yuyang-long/SSA/blob/HEAD/attack.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"Apache-2.0","inline_ok":true,"mcp_get_code":{"code_sha256":"56375b8dd939849e"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}