cs.CVSep 30, 2026

Let the Carrier Carry the Attack: Preserving the Subject in Adversarial Image Generation

Authors: Linfeng Jiang, Steven McDonagh, Yuhang Chen, Xingyu Zhao, Siddartha Khastgir, Andi Zhang

Organizations: University of Maryland, College Park · University of Edinburgh · WMG, University of Warwick · Wuhan University

Abstract

Strong unrestricted adversarial attacks can distort the primary object of an image, hereafter referred to as the subject. To preserve subject integrity without compromising attack magnitude, we introduce the carrier: a secondary visual element that provides an auxiliary region to facilitate the attack under global classifier guidance. We demonstrate three key findings: 1. A carrier mitigates subject distortion by absorbing a larger share of globally normalized attack updates. 2. A carrier improves cross-model transferability, governed by the strength of target-related features that balance semantic separation and transfer performance. 3. Successful targeted attacks retain the personalized subject as the primary content perceived by humans while successfully misleading the classifier. Our results demonstrate that a visually secondary carrier offers an auxiliary spatial pathway for adversarial changes, enabling strong and transferable attacks while improving subject preservation.

Figures & tables

Appendix figures & tables19 assets

Supplementary material from the paper’s appendix.

Appendix

Explore similar work

CardsList
  1. Information-Geometric Inverse Distillation for Enhancing Adversarial Transferability

    Feb 24, 2025Wenyuan Wu, Yuan Sun, Yingke Chen +4Adversarial TrainingDataset Distillation

  2. Season: Spectrum-Aware Orthogonal Gradient Refinement for Transfer-Based Adversarial Attacks

    Aug 5, 2026Tianyi Wang, Zhenghao Gao, Shengjie XuVision TransformerAttention-Guided Training

  3. Improving Adversarial Transferability on Vision-Language Pre-training Models via Surrogate-Specific Bias Correction

    Jun 9, 2026Lijia Yu, Jiuxin Cao, Yuchen Qiang +3Vision-Language Model AdaptationAdversarial Training