DFDS: Data-Free Dual Substitutes Hard-Label Black-Box Adversarial Attack

被引:0
|
作者
Jiang, Shuliang [1 ]
He, Yusheng [1 ]
Zhang, Rui [1 ]
Kang, Zi [1 ]
Xia, Hui [1 ]
机构
[1] Ocean Univ China, Fac Informat Sci & Engn, Qingdao 266100, Peoples R China
基金
中国国家自然科学基金;
关键词
Deep neural networks; Adversarial attack; White-box/black-box attack; Transfer-based adversarial attacks; Adversarial examples;
D O I
10.1007/978-981-97-5498-4_21
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Transfer-based hard-label black-box adversarial attacks, confront challenges in obtaining pertinent proxy datasets and demanding a substantial query volume to the target model without guaranteeing a high attack success rate. To address the challenges, we introduces the techniques of dual substitute model extraction and embedding space adversarial example search, proposing a novel hard-label black-box adversarial attack approach named Data-Free Dual Substitutes Hard-Label Black-Box Adversarial Attack (DFDS). This approach initially trains a generative adversarial network through adversarial training. This training is achieved without relying on proxy datasets, only depending on the hard-label outputs of the target model. Subsequently, it utilizes natural evolution strategy (NES) to conduct embedding space search for constructing the final adversarial examples. The comprehensive experimental results demonstrate that, under the same query volume, DFDS achieves higher attack success rates compared to baseline methods. In comparison to the state-of-the-art mixed-mechanism hard-label black-box attack approach DFMS-HL, DFDS exhibits significant improvements across the SVHN, CIFAR-10, and CIFAR-100 datasets. Significantly, in the targeted attack scenario on the CIFAR-10 dataset, the success rate reaches 76.59%, representing the highest enhancement of 21.99%.
引用
收藏
页码:274 / 285
页数:12
相关论文
共 50 条
  • [1] Hard-label Black-box Universal Adversarial Patch Attack
    Tao, Guanhong
    An, Shengwei
    Cheng, Siyuan
    Shen, Guangyu
    Zhang, Xiangyu
    [J]. PROCEEDINGS OF THE 32ND USENIX SECURITY SYMPOSIUM, 2023, : 697 - 714
  • [2] Data-free Universal Adversarial Perturbation and Black-box Attack
    Zhang, Chaoning
    Benz, Philipp
    Karjauv, Adil
    Kweon, In So
    [J]. 2021 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2021), 2021, : 7848 - 7857
  • [3] Data-Free Adversarial Perturbations for Practical Black-Box Attack
    Huan, Zhaoxin
    Wang, Yulong
    Zhang, Xiaolu
    Shang, Lin
    Fu, Chilin
    Zhou, Jun
    [J]. ADVANCES IN KNOWLEDGE DISCOVERY AND DATA MINING, PAKDD 2020, PT II, 2020, 12085 : 127 - 138
  • [4] Data-Free Hard-Label Robustness Stealing Attack
    Yuan, Xiaojian
    Chen, Kejiang
    Huang, Wen
    Zhang, Jie
    Zhang, Weiming
    Yu, Nenghai
    [J]. THIRTY-EIGHTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, VOL 38 NO 7, 2024, : 6853 - 6861
  • [5] HQA-Attack: Toward High Quality Black-Box Hard-Label Adversarial Attack on Text
    Liu, Han
    Xu, Zhi
    Zhang, Xiaotong
    Zhang, Feng
    Ma, Fenglong
    Chen, Hongyang
    Yu, Hong
    Zhang, Xianchao
    [J]. ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 36 (NEURIPS 2023), 2023,
  • [6] PAT: Geometry-Aware Hard-Label Black-Box Adversarial Attacks on Text
    Ye, Muchao
    Chen, Jinghui
    Miao, Chenglin
    Liu, Han
    Wang, Ting
    Ma, Fenglong
    [J]. PROCEEDINGS OF THE 29TH ACM SIGKDD CONFERENCE ON KNOWLEDGE DISCOVERY AND DATA MINING, KDD 2023, 2023, : 3093 - 3104
  • [7] HyGloadAttack: Hard-label black-box textual adversarial attacks via hybrid optimization
    Liu, Zhaorong
    Xiong, Xi
    Li, Yuanyuan
    Yu, Yan
    Lu, Jiazhong
    Zhang, Shuai
    Xiong, Fei
    [J]. NEURAL NETWORKS, 2024, 178
  • [8] Semantic-Aware Adaptive Binary Search for Hard-Label Black-Box Attack
    Ma, Yiqing
    Lucke, Kyle
    Xian, Min
    Vakanski, Aleksandar
    [J]. COMPUTERS, 2024, 13 (08)
  • [9] A Hard Label Black-box Adversarial Attack Against Graph Neural Networks
    Mu, Jiaming
    Wang, Binghui
    Li, Qi
    Sun, Kun
    Xu, Mingwei
    Liu, Zhuotao
    [J]. CCS '21: PROCEEDINGS OF THE 2021 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2021, : 108 - 125
  • [10] DST: Dynamic Substitute Training for Data-free Black-box Attack
    Wang, Wenxuan
    Qian, Xuelin
    Fu, Yanwei
    Xue, Xiangyang
    [J]. 2022 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2022, : 14341 - 14350