C/R-PMGAN: A dual-path self-supervised and patch-masked generative adversarial network for transferable black-box attack.
Journal:
Neural networks : the official journal of the International Neural Network Society
Published Date:
Feb 25, 2026
Abstract
Generative Adversarial Networks (GANs) are widely applied for generating various types of data (e.g., images, text, audio). Accordingly, its excellent performance has led to the broad adoption of GAN-based adversarial attack methods in black-box scenarios. The importance of transferable black-box attacks lies in their ability to be effective across different models and settings, more closely aligning with real-world applications. However, traditional gradient-based transferable attacks are inefficiently optimized and prone to overfitting surrogate models, while existing GAN-based generative methods still struggle to achieve strong cross-model feature alignment. To address these issues, we propose a novel algorithm named C/R-PMGAN to enhance the transferability of adversarial examples whilst improving the algorithm's efficiency. Specifically, a dual-path self-supervised task (contrastive learning vs. rotation classification) is introduced in the discriminator to learn more diverse and robust feature representations. Meanwhile, we propose a gradient aggregation strategy based on random patch-masking, which selects critical intermediate feature channels to guide the generator in focusing perturbations on cross-model shared semantic information. Extensive experimental evaluation demonstrates the effectiveness and superior performance of the proposed C/R-PMGAN, i.e., achieving the highest average attack success rate across 16 black-box models (including vision transformers and defense training models), while outperforming the state-of-the-art transferable attacks in both generation efficiency and perturbation imperceptibility.
Authors
Keywords
No keywords available for this article.