Existing adversarial attacks for face anti-spoofing predominantly assume that the model parameters are fully known, and often overlook the transferability of adversarial examples across different models and domains. Furthermore, they typically target relatively homogeneous architectures, relying primarily on basic deep learning models for anti-spoofing. To address these limitations, this paper proposes an illumination-based input transformation method for generating adversarial attacks. A liveness ablation module is introduced to suppress liveness-related cues in the input image prior to attack generation, thereby enhancing the adversarial strength of the crafted examples. Additionally, a random illumination transformation strategy is employed to increase domain divergence by altering illumination factors, which enriches the diversity of input samples and boosts the transferability of adversarial examples across different models and settings. Extensive experiments conducted on two public datasets demonstrate that the proposed method outperforms existing approaches in terms of physical-world transferability. Moreover, the liveness ablation module can be integrated with other attack strategies to furture improve their adversarial effectiveness.