Zhengzhao Pan, Xiaogang Zhang, Hua Chen, Qianyu Chen, Shengjie Hu
Unrestricted Adversarial Examples (UAEs) pose a growing security challenge to Deep Neural Networks by introducing substantial, semantically natural modifications to images. While current diffusion-based methods improve the naturalness of UAEs, they suffer from two key limitations: an underutilization of the diffusion model's learned data distribution, which caps sample quality, and a lack of flexibility for diverse attack scenarios. To address these issues, we reframe the UAE generation as a Bayesian inference problem, leveraging a pre-trained diffusion model as a powerful prior to ensure UAEs are statistically consistent with real data and therefore improve their effectiveness and naturalness. Building upon this foundation, we introduce DiffAdvMAP+, an enhanced framework featuring a novel sample-specific adaptive mechanism. This module dynamically tunes key parameters, such as the diffusion step and adversarial confidence level, based on individual image complexity, thereby boosting both efficacy and efficiency. This principled approach, combining a flexible reconstruction constraint with sample-specific adaptation, allows DiffAdvMAP+ to excel at diverse tasks, including noise-originating and image-similar attacks. Extensive experiments conducted on various model structures, datasets, and defense methods demonstrate that our method achieves a favorable overall trade-off between image quality, flexibility, and transferability compared to existing approaches.