A Black-Box Attack Algorithm Targeting Unlabeled Industrial AI Systems With Contrastive Learning

被引:0
|
作者
Duan, Mingxing [1 ,2 ]
Xiao, Guoqing [1 ,2 ]
Li, Kenli [1 ]
Xiao, Bin [3 ]
机构
[1] Hunan Univ, Sch Informat Sci & Engn, Changsha 410082, Peoples R China
[2] Hunan Univ, Shenzhen Inst, Shenzhen 518063, Peoples R China
[3] Hong Kong Polytech Univ, Dept Comp, Hong Kong, Peoples R China
关键词
Adversarial examples; contrastive learning (CL); industrial AI models; limited queries; robustness;
D O I
10.1109/TII.2023.3345472
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Adversarial attack algorithms are useful for testing and improving the robustness of industrial AI models. However, attacking black-box models with limited queries and unknown real labels remains a significant challenge. To overcome this challenge, we propose using contrastive learning to train a generated substitute model called attack contrastive learning network (ACL-Net) to attack black-box models with very few queries and no real labels. ACL-Net achieves end-to-end contrastive learning during training without labels, which differs from previous contrastive learning methods that required separate training for the classification layer with labels. We improve ACL-Net's robustness by using adversarial examples to train it during the attack stage. This approach results in more effective adversarial examples generated by ACL-Net. We conducted extensive experiments to validate the effectiveness of ACL-Net. Compared with the latest algorithms, ACL-Net requires fewer queries to achieve better attack performance, demonstrating its superiority in query-efficient black-box attacks. Overall, our approach presents a promising solution to the challenge of attacking black-box models with limited queries and unknown real labels. Our results show the effectiveness of using contrastive learning to train generated substitute models, and the potential for improving the robustness of industrial AI models through adversarial attacks.
引用
收藏
页码:6325 / 6335
页数:11
相关论文
共 50 条
  • [1] Spanning attack: reinforce black-box attacks with unlabeled data
    Wang, Lu
    Zhang, Huan
    Yi, Jinfeng
    Hsieh, Cho-Jui
    Jiang, Yuan
    [J]. MACHINE LEARNING, 2020, 109 (12) : 2349 - 2368
  • [2] Spanning attack: reinforce black-box attacks with unlabeled data
    Lu Wang
    Huan Zhang
    Jinfeng Yi
    Cho-Jui Hsieh
    Yuan Jiang
    [J]. Machine Learning, 2020, 109 : 2349 - 2368
  • [3] Research on Black-box Attack Algorithm by Targeting ID Card Text Recognition
    Xu, Chang-Kai
    Feng, Wei-Dong
    Zhang, Chun-Jie
    Zheng, Xiao-Long
    Zhang, Hui
    Wang, Fei-Yue
    [J]. Zidonghua Xuebao/Acta Automatica Sinica, 2024, 50 (01): : 103 - 120
  • [4] Sparse Black-Box Video Attack with Reinforcement Learning
    Xingxing Wei
    Huanqian Yan
    Bo Li
    [J]. International Journal of Computer Vision, 2022, 130 : 1459 - 1473
  • [5] Sparse Black-Box Video Attack with Reinforcement Learning
    Wei, Xingxing
    Yan, Huanqian
    Li, Bo
    [J]. INTERNATIONAL JOURNAL OF COMPUTER VISION, 2022, 130 (06) : 1459 - 1473
  • [6] Generalizable Black-Box Adversarial Attack With Meta Learning
    Yin, Fei
    Zhang, Yong
    Wu, Baoyuan
    Feng, Yan
    Zhang, Jingyi
    Fan, Yanbo
    Yang, Yujiu
    [J]. IEEE TRANSACTIONS ON PATTERN ANALYSIS AND MACHINE INTELLIGENCE, 2024, 46 (03) : 1804 - 1818
  • [7] Challenges of Explaining the Behavior of Black-Box AI Systems
    Asatiani, Aleksandre
    Malo, Pekka
    Nagb, Per Radberg
    Penttinen, Esko
    Rinta-Kahila, Tapani
    Salovaara, Antti
    [J]. MIS QUARTERLY EXECUTIVE, 2020, 19 (04) : 259 - 278
  • [8] Optimized Gradient Boosting Black-Box Adversarial Attack Algorithm
    Liu, Mengting
    Ling, Jie
    [J]. Computer Engineering and Applications, 2023, 59 (18) : 260 - 267
  • [9] Substitute Meta-Learning for Black-Box Adversarial Attack
    Hu, Cong
    Xu, Hao-Qi
    Wu, Xiao-Jun
    [J]. IEEE SIGNAL PROCESSING LETTERS, 2022, 29 : 2472 - 2476
  • [10] Black-box attack against GAN-generated image detector with contrastive perturbation
    Lou, Zijie
    Cao, Gang
    Lin, Man
    [J]. ENGINEERING APPLICATIONS OF ARTIFICIAL INTELLIGENCE, 2023, 124