Decision-Based Query Efficient Adversarial Attack via Adaptive Boundary Learning

被引:0
|
作者
Shen, Meng [1 ]
Li, Changyue [1 ]
Yu, Hao [2 ]
Li, Qi [3 ]
Zhu, Liehuang [1 ]
Xu, Ke [4 ]
机构
[1] Beijing Inst Technol, Sch Cyberspace Sci & Technol, Beijing 100081, Peoples R China
[2] Natl Univ Def Technol, Coll Comp, Changsha 2410073, Peoples R China
[3] Tsinghua Univ, Inst Network Sci & Cyberspace, Beijing 100190, Peoples R China
[4] Tsinghua Univ, Dept Comp Sci, Beijing 100190, Peoples R China
基金
国家重点研发计划; 北京市自然科学基金;
关键词
Adaptation models; Perturbation methods; Optimization; Training; Task analysis; Predictive models; Metalearning; Adversarial attack; black-box attack; decision-based; meta-learning; query efficiency;
D O I
10.1109/TDSC.2023.3289298
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Decision-based adversarial attacks pose a severe threat to real-world applications of Deep Neural Networks (DNNs), as attackers are assumed to have no prior knowledge about target model except hard labels of model outputs. Existing decision-based attacks require a large number of queries on the target model for a successful attack. In this article, we propose DEAL, a decision-based query efficient adversarial attack based on adaptive boundary learning. DEAL relies on a local model initialized through meta-learning mechanism to obtain the ability to fit new decision boundaries. We conduct extensive experiments to evaluate the effectiveness of DEAL, which demonstrates that it outperforms 8 state-of-the-art attacks. Specifically for the evaluation on CIFAR-10 dataset, DEAL achieves similar attack success rates with a maximum query reduction of 51% in untargeted attacks and 14% in targeted attacks, respectively.
引用
收藏
页码:1740 / 1753
页数:14
相关论文
共 50 条
  • [1] Triangle Attack: A Query-Efficient Decision-Based Adversarial Attack
    Wang, Xiaosen
    Zhang, Zeliang
    Tong, Kangheng
    Gong, Dihong
    He, Kun
    Li, Zhifeng
    Liu, Andwei
    [J]. COMPUTER VISION - ECCV 2022, PT V, 2022, 13665 : 156 - 174
  • [2] HopSkipJumpAttack: A Query-Efficient Decision-Based Attack
    Chen, Jianbo
    Jordan, Michael, I
    Wainwright, Martin J.
    [J]. 2020 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP 2020), 2020, : 1277 - 1294
  • [3] Query-efficient decision-based attack via sampling distribution reshaping
    Sun, Xuxiang
    Cheng, Gong
    Pei, Lei
    Han, Junwei
    [J]. PATTERN RECOGNITION, 2022, 129
  • [4] FaDec: A Fast Decision-based Attack for Adversarial Machine Learning
    Khalid, Faiq
    Ali, Hassan
    Hanif, Muhammad Abdullah
    Rehman, Semeen
    Ahmed, Rehan
    Shafique, Muhammad
    [J]. 2020 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS (IJCNN), 2020,
  • [5] Decision-Based Adversarial Attack With Frequency Mixup
    Li, Xiu-Chuan
    Zhang, Xu-Yao
    Yin, Fei
    Liu, Cheng-Lin
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2022, 17 : 1038 - 1052
  • [6] Decision-Based Adversarial Attack with Frequency Mixup
    Li, Xiu-Chuan
    Zhang, Xu-Yao
    Yin, Fei
    Liu, Cheng-Lin
    [J]. IEEE Transactions on Information Forensics and Security, 2022, 17 : 1038 - 1052
  • [7] DAIR: A Query-Efficient Decision-based Attack on Image Retrieval Systems
    Chen, Mingyang
    Lu, Junda
    Wang, Yi
    Qin, Jianbin
    Wang, Wei
    [J]. SIGIR '21 - PROCEEDINGS OF THE 44TH INTERNATIONAL ACM SIGIR CONFERENCE ON RESEARCH AND DEVELOPMENT IN INFORMATION RETRIEVAL, 2021, : 1064 - 1073
  • [8] Query-Efficient Decision-Based Black-Box Patch Attack
    Chen, Zhaoyu
    Li, Bo
    Wu, Shuang
    Ding, Shouhong
    Zhang, Wenqiang
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2023, 18 : 5522 - 5536
  • [9] QESAR: Query Effective Decision-Based Attack on Skeletal Action Recognition
    Kang, Zi
    Zhang, Yumei
    Zhang, Rui
    Jiang, Yanan
    Xia, Hui
    [J]. PATTERN RECOGNITION AND COMPUTER VISION, PRCV 2023, PT VIII, 2024, 14432 : 417 - 429
  • [10] ADDA: An Adversarial Direction-Guided Decision-Based Attack via Multiple Surrogate Models
    Li, Wanman
    Liu, Xiaozhang
    [J]. MATHEMATICS, 2023, 11 (16)