Semantic-Aware Adaptive Binary Search for Hard-Label Black-Box Attack

被引:0
|
作者
Ma, Yiqing [1 ]
Lucke, Kyle [2 ]
Xian, Min [2 ]
Vakanski, Aleksandar [2 ,3 ]
机构
[1] Univ Utah, Huntsman Canc Inst, Salt Lake City, UT 84112 USA
[2] Univ Idaho, Dept Comp Sci, Idaho Falls, ID 83402 USA
[3] Univ Idaho, Dept Nucl Engn & Ind Management, Idaho Falls, ID 83402 USA
关键词
adversarial attack; hard-label black-box attack; adaptive binary search; breast ultrasound; semantic-aware search;
D O I
10.3390/computers13080203
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Despite the widely reported potential of deep neural networks for automated breast tumor classification and detection, these models are vulnerable to adversarial attacks, which leads to significant performance degradation on different datasets. In this paper, we introduce a novel adversarial attack approach under the decision-based black-box setting, where the attack does not have access to the model parameters, and the returned information from querying the target model consists of only the final class label prediction (i.e., hard-label attack). The proposed attack approach has two major components: adaptive binary search and semantic-aware search. The adaptive binary search utilizes a coarse-to-fine strategy that applies adaptive tolerance values in different searching stages to reduce unnecessary queries. The proposed semantic mask-aware search crops the search space by using breast anatomy, which significantly avoids invalid searches. We validate the proposed approach using a dataset of 3378 breast ultrasound images and compare it with another state-of-the-art method by attacking five deep learning models. The results demonstrate that the proposed approach generates imperceptible adversarial samples at a high success rate (between 99.52% and 100%), and dramatically reduces the average and median queries by 23.96% and 31.79%, respectively, compared with the state-of-the-art approach.
引用
收藏
页数:14
相关论文
共 36 条
  • [21] Black-Box Adversarial Attack via Topological Adaptive Particle Swarm Optimization
    Yu Z.
    Kang J.
    Ye O.
    Jisuanji Fuzhu Sheji Yu Tuxingxue Xuebao/Journal of Computer-Aided Design and Computer Graphics, 2023, 35 (08): : 1239 - 1248
  • [22] BFS2Adv: Black-box adversarial attack towards hard-to-attack short texts
    Han, Xu
    Li, Qiang
    Cao, Hongbo
    Han, Lei
    Wang, Bin
    Bao, Xuhua
    Han, Yufei
    Wang, Wei
    COMPUTERS & SECURITY, 2024, 141
  • [23] A Parallel Adaptive Swarm Search Framework for Solving Black-Box Optimization Problems
    Shuka, Romeo
    Brehm, Juergen
    ARCHITECTURE OF COMPUTING SYSTEMS - ARCS 2019, 2019, 11479 : 100 - 111
  • [24] A Context-aware Black-box Adversarial Attack for Deep Driving Maneuver Classification Models
    Sarker, Ankur
    Shen, Haiying
    Sen, Tanmoy
    2021 18TH ANNUAL IEEE INTERNATIONAL CONFERENCE ON SENSING, COMMUNICATION, AND NETWORKING (SECON), 2021,
  • [25] Object-Aware Transfer-Based Black-Box Adversarial Attack on Object Detector
    Leng, Zhuo
    Cheng, Zesen
    Wei, Pengxu
    Chen, Jie
    PATTERN RECOGNITION AND COMPUTER VISION, PRCV 2023, PT XII, 2024, 14436 : 278 - 289
  • [26] Simple and Efficient Hard Label Black-box Adversarial Attacks in Low Query Budget Regimes
    Shukla, Satya Narayan
    Sahu, Anit Kumar
    Willmott, Devin
    Kolter, Zico
    KDD '21: PROCEEDINGS OF THE 27TH ACM SIGKDD CONFERENCE ON KNOWLEDGE DISCOVERY & DATA MINING, 2021, : 1461 - 1469
  • [27] Predicting the utility of search spaces for black-box optimization: a simple, budget-aware approach
    Ariafar, Setareh
    Gilmer, Justin
    Nado, Zachary
    Snoek, Jasper
    Jenatton, Rodolphe
    Dahl, George E.
    INTERNATIONAL CONFERENCE ON ARTIFICIAL INTELLIGENCE AND STATISTICS, VOL 151, 2022, 151
  • [28] A QUANTILE ADAPTIVE SEARCH FOR BLACK-BOX SIMULATION OPTIMIZATION ON CONTINUOUS DOMAINS WITH PRACTICAL IMPLEMENTATIONS
    Linz, David
    2017 WINTER SIMULATION CONFERENCE (WSC), 2017, : 4614 - 4615
  • [29] Aha! Adaptive History-driven Attack for Decision-based Black-box Models
    Li, Jie
    Ji, Rongrong
    Chen, Peixian
    Zhang, Baochang
    Hong, Xiaopeng
    Zhang, Ruixin
    Li, Shaoxin
    Li, Jilin
    Huang, Feiyue
    Wu, Yongjian
    2021 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2021), 2021, : 16148 - 16157
  • [30] FeatureBA: Hard label black box attack based on internal layer features of surrogate model
    Li, Jiaxing
    Tan, Yu-an
    Liu, Runke
    Meng, Weizhi
    Li, Yuanzhang
    Expert Systems with Applications, 2025, 276