Blackbox Attacks via Surrogate Ensemble Search

被引:0
|
作者
Cai, Zikui [1 ]
Song, Chengyu [1 ]
Krishnamurthy, Srikanth [1 ]
Roy-Chowdhury, Amit [1 ]
Asif, M. Salman [1 ]
机构
[1] Univ Calif Riverside, Riverside, CA 92521 USA
关键词
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Blackbox adversarial attacks can be categorized into transfer- and query-based attacks. Transfer methods do not require any feedback from the victim model, but provide lower success rates compared to query-based methods. Query attacks often require a large number of queries for success. To achieve the best of both approaches, recent efforts have tried to combine them, but still require hundreds of queries to achieve high success rates (especially for targeted attacks). In this paper, we propose a novel method for Blackbox Attacks via Surrogate Ensemble Search (BASES) that can generate highly successful blackbox attacks using an extremely small number of queries. We first define a perturbation machine that generates a perturbed image by minimizing a weighted loss function over a fixed set of surrogate models. To generate an attack for a given victim model, we search over the weights in the loss function using queries generated by the perturbation machine. Since the dimension of the search space is small (same as the number of surrogate models), the search requires a small number of queries. We demonstrate that our proposed method achieves better success rate with at least 30x fewer queries compared to state-of-the-art methods on different image classifiers trained with ImageNet (including VGG-19, DenseNet-121, and ResNext-50). In particular, our method requires as few as 3 queries per image (on average) to achieve more than a 90% success rate for targeted attacks and 1-2 queries per image for over a 99% success rate for untargeted attacks. Our method is also effective on Google Cloud Vision API and achieved a 91% untargeted attack success rate with 2.9 queries per image. We also show that the perturbations generated by our proposed method are highly transferable and can be adopted for hard-label blackbox attacks. Furthermore, we argue that BASES can be used to create attacks for a variety of tasks and show its effectiveness for attacks on object detection models. Our code is available at https://github.com/CSIPlab/BASES.
引用
收藏
页数:15
相关论文
共 50 条
  • [41] Investigating rarity in web attacks with ensemble learners
    Zuech, Richard
    Hancock, John
    Khoshgoftaar, Taghi M.
    JOURNAL OF BIG DATA, 2021, 8 (01)
  • [42] Investigating rarity in web attacks with ensemble learners
    Richard Zuech
    John Hancock
    Taghi M. Khoshgoftaar
    Journal of Big Data, 8
  • [43] Recursive Modified Pattern Search on High-Dimensional Simplex : A Blackbox Optimization Technique
    Priyam Das
    Sankhya B, 2021, 83 : 440 - 483
  • [44] Local Ensemble Surrogate Assisted Crowding Differential Evolution
    Jin, Chen
    Qin, A. K.
    Tang, Ke
    2015 IEEE CONGRESS ON EVOLUTIONARY COMPUTATION (CEC), 2015, : 433 - 440
  • [45] Catch Me If You Can: Blackbox Adversarial Attacks on Automatic Speech Recognition using Frequency Masking
    Wu, Xiaoliang
    Rajan, Ajitha
    2022 29TH ASIA-PACIFIC SOFTWARE ENGINEERING CONFERENCE, APSEC, 2022, : 169 - 178
  • [46] Surrogate Model Assisted Ensemble Differential Evolution Algorithm
    Mallipeddi, Rammohan
    Lee, Minho
    2012 IEEE CONGRESS ON EVOLUTIONARY COMPUTATION (CEC), 2012,
  • [47] Ensemble Surrogate Models for Fast LIB Performance Predictions
    Quartulli, Marco
    Gil, Amaia
    Florez-Tapia, Ane Miren
    Cereijo, Pablo
    Ayerbe, Elixabete
    Olaizola, Igor G.
    ENERGIES, 2021, 14 (14)
  • [48] Ensemble surrogate models for fast lib performance predictions
    Quartulli, Marco (mquartulli@vicomtech.org), 1600, MDPI AG (14):
  • [49] Robust optimization of noisy blackbox problems using the Mesh Adaptive Direct Search algorithm
    Charles Audet
    Amina Ihaddadene
    Sébastien Le Digabel
    Christophe Tribes
    Optimization Letters, 2018, 12 : 675 - 689
  • [50] Robust optimization of noisy blackbox problems using the Mesh Adaptive Direct Search algorithm
    Audet, Charles
    Ihaddadene, Amina
    Le Digabel, Sebastien
    Tribes, Christophe
    OPTIMIZATION LETTERS, 2018, 12 (04) : 675 - 689