Blackbox Attacks via Surrogate Ensemble Search

被引:0
|
作者
Cai, Zikui [1 ]
Song, Chengyu [1 ]
Krishnamurthy, Srikanth [1 ]
Roy-Chowdhury, Amit [1 ]
Asif, M. Salman [1 ]
机构
[1] Univ Calif Riverside, Riverside, CA 92521 USA
关键词
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Blackbox adversarial attacks can be categorized into transfer- and query-based attacks. Transfer methods do not require any feedback from the victim model, but provide lower success rates compared to query-based methods. Query attacks often require a large number of queries for success. To achieve the best of both approaches, recent efforts have tried to combine them, but still require hundreds of queries to achieve high success rates (especially for targeted attacks). In this paper, we propose a novel method for Blackbox Attacks via Surrogate Ensemble Search (BASES) that can generate highly successful blackbox attacks using an extremely small number of queries. We first define a perturbation machine that generates a perturbed image by minimizing a weighted loss function over a fixed set of surrogate models. To generate an attack for a given victim model, we search over the weights in the loss function using queries generated by the perturbation machine. Since the dimension of the search space is small (same as the number of surrogate models), the search requires a small number of queries. We demonstrate that our proposed method achieves better success rate with at least 30x fewer queries compared to state-of-the-art methods on different image classifiers trained with ImageNet (including VGG-19, DenseNet-121, and ResNext-50). In particular, our method requires as few as 3 queries per image (on average) to achieve more than a 90% success rate for targeted attacks and 1-2 queries per image for over a 99% success rate for untargeted attacks. Our method is also effective on Google Cloud Vision API and achieved a 91% untargeted attack success rate with 2.9 queries per image. We also show that the perturbations generated by our proposed method are highly transferable and can be adopted for hard-label blackbox attacks. Furthermore, we argue that BASES can be used to create attacks for a variety of tasks and show its effectiveness for attacks on object detection models. Our code is available at https://github.com/CSIPlab/BASES.
引用
收藏
页数:15
相关论文
共 50 条
  • [21] Query-efficient black-box ensemble attack via dynamic surrogate weighting
    Hu, Cong
    He, Zhichao
    Wu, Xiaojun
    PATTERN RECOGNITION, 2025, 161
  • [22] Secured Cluster-Based Electricity Theft Detectors Against Blackbox Evasion Attacks
    Elgarhy, Islam
    El-Toukhy, Ahmed T.
    Badr, Mahmoud M.
    Mahmoud, Mohamed
    Fouda, Mostafa M.
    Alsabaan, Maazen
    Kholidy, Hisham A.
    2024 IEEE 21ST CONSUMER COMMUNICATIONS & NETWORKING CONFERENCE, CCNC, 2024, : 333 - 338
  • [23] Stochastic mesh adaptive direct search for blackbox optimization using probabilistic estimates
    Charles Audet
    Kwassi Joseph Dzahini
    Michael Kokkolaras
    Sébastien Le Digabel
    Computational Optimization and Applications, 2021, 79 : 1 - 34
  • [24] A First Look at Generating Website Fingerprinting Attacks via Neural Architecture Search
    Singh, Prabhjot
    Naik, Shreya Arun
    Malekghaini, Navid
    Barradas, Diogo
    Limam, Noura
    PROCEEDINGS OF THE 22ND WORKSHOP ON PRIVACY IN THE ELECTRONIC SOCIETY, WPES 2023, 2023, : 173 - 178
  • [25] Efficient ensemble to combat flash attacks
    Kumar, Om C. U.
    Bhama, Ponsy R. K. Sathia
    COMPUTATIONAL INTELLIGENCE, 2024, 40 (01)
  • [26] Ensemble Methods to Detect XSS Attacks
    Nagarjun, P. M. D.
    Ahamad, Shaik Shakeel
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2020, 11 (05) : 695 - 700
  • [27] Crystal Polymorph Search in the NPT Ensemble via a Deposition/Sublimation Alchemical Path
    Nessler, Aaron J.
    Okada, Okimasa
    Kinoshita, Yuya
    Nishimura, Koki
    Nagata, Hiroomi
    Fukuzawa, Kaori
    Yonemochi, Etsuo
    Schnieders, Michael J.
    CRYSTAL GROWTH & DESIGN, 2024, 24 (08) : 3205 - 3217
  • [28] A Pointwise-Optimal Ensemble of Surrogate Models
    Liang, Pengwei
    Zhang, Shuai
    Pang, Yong
    Li, Jianji
    Song, Xueguan
    JOURNAL OF MECHANICAL DESIGN, 2023, 145 (11)
  • [29] A Surrogate Ensemble Study of Sea Level Reconstructions
    Christiansen, Bo
    Schmith, T.
    Thejll, P.
    JOURNAL OF CLIMATE, 2010, 23 (16) : 4306 - 4326
  • [30] Boosting Targeted Black-Box Attacks via Ensemble Substitute Training and Linear Augmentation
    Gao, Xianfeng
    Tan, Yu-an
    Jiang, Hongwei
    Zhang, Quanxin
    Kuang, Xiaohui
    APPLIED SCIENCES-BASEL, 2019, 9 (11):