Query-Efficient Generation of Adversarial Examples for Defensive DNNs via Multiobjective Optimization

被引:0
|
作者
Jiang, Wei [1 ]
You, Shen [1 ]
Zhan, Jinyu [1 ]
Wang, Xupeng [1 ]
Lei, Hong [1 ]
Adhikari, Deepak [1 ]
机构
[1] Univ Elect Sci & Technol China, Sch Informat & Software Engn, Chengdu 610054, Peoples R China
关键词
Black-box adversarial example (AE); defensive deep neural networks (DNNs); genetic algorithm (GA); multiobjective optimization;
D O I
10.1109/TEVC.2022.3231460
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Due to the inherent vulnerability of deep neural networks (DNNs), the adversarial example (AE) attack has become a serious threat to intelligent systems, e.g., the failure cause of an image classification system. Different to existing works, in this article we are interested in the generation of AEs for DNNs with defensive mechanisms. To make the attack more practical, we exploit a query-based method to generate image AEs in a black-box attack setting. Considering that the generation of AEs is inherently a constrained optimization problem, this article first formulates three objectives regarding defensive DNNs, i.e., attack effectiveness, attack evasiveness and attack coverage. Then, this article proposes a query-efficient AE attack based on the genetic algorithm (GA) and particle swarm optimization (PSO) to address the perturbation optimization problem. To improve the efficiency of search and query, AE-specific operators including block-level and pixel-level crossovers, discrete perturbation mutation and direction-driven reproduction are designed within the GA-based search framework. In addition, predication-based adaptation of reproduction-related parameters is implemented to speed up the search convergence. PSO-based jumping process is further devised to avoid stuck in local optimum. Benchmark-based experiments evaluated the efficiency of our method, which can achieve an attack success rate of 100% with averagely 52.95% reduced queries in contrast to existing black-box attacks on nondefensive models. For defensive DNN models, our method can obtain top attack performance with the query reduction up to 70.92% comparing with the candidates.
引用
收藏
页码:832 / 847
页数:16
相关论文
共 50 条
  • [1] QE-DBA: Query-Efficient Decision-Based Adversarial Attacks via Bayesian Optimization
    Zhang, Zhuosheng
    Ahmed, Noor
    Yu, Shucheng
    2024 INTERNATIONAL CONFERENCE ON COMPUTING, NETWORKING AND COMMUNICATIONS, ICNC, 2024, : 783 - 788
  • [2] Query-Efficient and Scalable Black-Box Adversarial Attacks on Discrete Sequential Data via Bayesian Optimization
    Lee, Deokjae
    Moon, Seungyong
    Lee, Junhyeok
    Song, Hyun Oh
    INTERNATIONAL CONFERENCE ON MACHINE LEARNING, VOL 162, 2022,
  • [3] QUERY-EFFICIENT ADVERSARIAL ATTACK BASED ON LATIN HYPERCUBE SAMPLING
    Wang, Dan
    Lin, Jiayu
    Wang, Yuan-Gen
    2022 IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING, ICIP, 2022, : 546 - 550
  • [4] DifAttack: Query-Efficient Black-Box Adversarial Attack via Disentangled Feature Space
    Liu, Jun
    Zhou, Jiantao
    Zeng, Jiandian
    Tian, Jinyu
    THIRTY-EIGHTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, VOL 38 NO 4, 2024, : 3666 - 3674
  • [5] Query-Efficient Black-Box Red Teaming via Bayesian Optimization
    Lee, Deokjae
    Lee, JunYeong
    Ha, Jung-Woo
    Kim, Jin-Hwa
    Lee, Sang-Woo
    Lee, Hwaran
    Song, Hyun Oh
    PROCEEDINGS OF THE 61ST ANNUAL MEETING OF THE ASSOCIATION FOR COMPUTATIONAL LINGUISTICS (ACL 2023): LONG PAPERS, VOL 1, 2023, : 11551 - 11574
  • [6] Triangle Attack: A Query-Efficient Decision-Based Adversarial Attack
    Wang, Xiaosen
    Zhang, Zeliang
    Tong, Kangheng
    Gong, Dihong
    He, Kun
    Li, Zhifeng
    Liu, Andwei
    COMPUTER VISION - ECCV 2022, PT V, 2022, 13665 : 156 - 174
  • [7] SAM: Query-efficient Adversarial Attacks against Graph Neural Networks
    Zhang, Chenhan
    Zhang, Shiyao
    Yu, James J. Q.
    Yu, Shui
    ACM TRANSACTIONS ON PRIVACY AND SECURITY, 2023, 26 (04)
  • [8] Towards Query-Efficient Adversarial Attacks Against Automatic Speech Recognition Systems
    Wang, Qian
    Zheng, Baolin
    Li, Qi
    Shen, Chao
    Ba, Zhongjie
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2021, 16 : 896 - 908
  • [9] Query-Efficient Black-Box Adversarial Attack with Random Pattern Noises
    Yuito, Makoto
    Suzuki, Kenta
    Yoneyama, Kazuki
    INFORMATION AND COMMUNICATIONS SECURITY, ICICS 2022, 2022, 13407 : 303 - 323
  • [10] Transferable adversarial distribution learning: Query-efficient adversarial attack against large language models
    Dong, Huoyuan
    Dong, Jialiang
    Wan, Shaohua
    Yuan, Shuai
    Guan, Zhitao
    COMPUTERS & SECURITY, 2023, 135