PAR-AdvGAN: Improving Adversarial Attack Capability with Progressive Auto-Regression AdvGAN (Extended Abstract)
PAR-AdvGAN: Improving Adversarial Attack Capability with Progressive Auto-Regression AdvGAN (Extended Abstract)
Jiayu Zhang, Zhiyu Zhu, Xinyi Wang, Silin Liao, Zhibo Jin, Flora Salim, Huaming Chen
Proceedings of the Thirty-Fifth International Joint Conference on Artificial Intelligence
Sister Conferences Best Papers. Pages 8301-8305.
https://doi.org/10.24963/ijcai.2026/930
Deep neural networks are vulnerable to adversarial examples, posing serious security risks. While GAN-based attacks such as AdvGAN enable fast adversarial example generation, they typically operate in a single step, limiting attack effectiveness and transferability. In this work, we propose PAR-AdvGAN, a progressive auto-regressive GAN framework that iteratively refines adversarial perturbations. By conditioning each iteration on the previous output, PAR-AdvGAN produces stronger, more transferable attacks while maintaining low visual distortion and high generation speed. Experiments on multiple models and datasets demonstrate that PAR-AdvGAN significantly outperforms baseline methods in attack success rate, achieving up to 335.5 frames per second, highlighting its practical efficiency for black-box attack scenarios.
Keywords:
AI Ethics, Trust, Fairnes: Trustworthy AI
AI Ethics, Trust, Fairnes: Safety and robustness
Machine Learning: Trustworthy machine learning
