SearcharxivSearch

arXiv · 2312.12556

Tensor Train Decomposition for Adversarial Attacks on Computer Vision Models

Abstract

Deep neural networks (DNNs) are widely used today, but they are vulnerable to adversarial attacks. To develop effective methods of defense, it is important to understand the potential weak spots of DNNs. Often attacks are organized taking into account the architecture of models (white-box approach) and based on gradient methods, but for real-world DNNs this approach in most cases is impossible. At the same time, several gradient-free optimization algorithms are used to attack black-box models. However, classical methods are often ineffective in the multidimensional case. To organize black-box attacks for computer vision models, in this work, we propose the use of an optimizer based on the low-rank tensor train (TT) format, which has gained popularity in various practical multidimensional applications in recent years. Combined with the attribution of the target image, which is built by the auxiliary (white-box) model, the TT-based optimization method makes it possible to organize an effective black-box attack by small perturbation of pixels in the target image. The superiority of the proposed approach over three popular baselines is demonstrated for seven modern DNNs on the ImageNet dataset.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Andrei Chertkov, Ivan Oseledets. 2025-08-21. Tensor Train Decomposition for Adversarial Attacks on Computer Vision Models. https://arxiv.org/abs/2312.12556

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

Stress-divergence, Laplacian, and rotational forms of the incompressible Navier--Stokes equations with variable viscosity

In the Navier--Stokes equations, incompressibility allows rewriting the viscous term in various forms leading to distinct numerical properties and flow descriptions. Furthermore, models accounting for non-Newtonian, thermal or turbulent effects often break the constant-viscosity assumption, thereby producing additional consistency terms. In this context, the present work compares the classical symmetric-gradient diffusion term with more recent variable-viscosity generalizations of the Laplacian and rotational forms. We discuss, analyze and test their differences with respect to implementation, efficiency, numerical stability and outflow boundary conditions. With a focus on time-dependent flows, we consider second-order implicit-explicit (IMEX) temporal discretizations aimed at improving efficiency and numerical stability. Through a rigorous stability analysis, we show how selected explicit treatments can bypass algorithmic nonlinearities without inducing CFL conditions. Our numerical results highlight important differences between the three viscous formulations---especially in the presence of outflow boundaries, for which the generalized Laplacian form proves more suitable in diffusion-dominated regimes. %(as widely known for constant viscosity).

math.NA

Full-window branch discovery and loss-selected EnKF continuation for data assimilation

We develop a framework for offline full-window branch discovery, optionally followed by online continuation with an ensemble Kalman filter (EnKF). Three mechanisms drive the branch search: adjoint path-kernel (APK) differentiation balances kernel differentiation and correction-stabilized path perturbation, shifting the optimization from exploration to exploitation; an optimized Gaussian initial law broadens the search over initial-state basins; and loss-weighted mixing across independent runs recombines successful path components. We may then select an interior state using a local loss and continue online with an EnKF. In 40-dimensional Lorenz-96 experiments, the mean offline path RMSE of APK is 4.3 times smaller than that of population weak-$\mathrm{4D\text{-}Var}_x$. The resulting APK-EnKF method has a mean online RMSE 64 times smaller than that of ordinary EnKF.

math.NA

A variational physics-informed graph neural network for heterogeneous solid mechanics

Stress localization in heterogeneous solids is governed by the bimaterial interface, where the displacement field remains $C^0$-continuous, while in-plane stresses jump due to the stiffness mismatch. Coordinate-based physics-informed neural networks (PINNs) represent this jump via a prescribed regularization width or a weighted interface penalty, making their accuracy sensitive to how phase-contrast changes are handled. This work presents a variational, label-free physics-informed graph neural network (PI-GNN) in which the heterogeneity is carried by the discretization rather than by the trial field. The solver operates on a conforming adaptive mesh graph, assigns constitutive behavior per element, and minimizes the discrete total potential energy as a single unweighted objective in which only first derivatives appear. The discrete energy on piecewise-linear elements coincides with the finite element (FE) Ritz functional. Dirichlet conditions are enforced by construction, with no penalty term, no interface weight, and no prescribed transition width. Using one fixed architecture, optimizer, and loss across small-strain elasticity and finite-strain Neo-Hookean hyperelasticity in two and three dimensions, the von Mises error remains below $3.58\%$ across a stiffness-contrast sweep spanning $(E_{\mathrm{inc}}/E_{\mathrm{mat}}\in[10^{-2},10^{2}])$, where a strong-form PINN degrades to $5.58\%$, and its displacement error reaches $7.66\%$ against $0.49\%$ for the PI-GNN. A trained network halves the ($\sigma_{xx}$) error of an energy-based PINN ($5.01\%$ versus $10.94\%$). Training cost exceeds a single FE solve by more than an order of magnitude, so the construction is a variationally consistent, penalty-free interface representation for parametric surrogates and inverse identification rather than a replacement for a one-off FE analysis.

math.NA