A Geometry-Inspired Decision-Based Attack

被引:31
|
作者
Liu, Yujia [1 ]
Moosavi-Dezfooli, Seyed-Mohsen [2 ]
Frossard, Pascal [2 ]
机构
[1] Univ Sci & Technol China, Hefei, Peoples R China
[2] Ecole Polytech Fed Lausanne, Lausanne, Switzerland
关键词
D O I
10.1109/ICCV.2019.00499
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Deep neural networks have recently achieved tremendous success in image classification. Recent studies have however shown that they are easily misled into incorrect classification decisions by adversarial examples. Adversaries can even craft attacks by querying the model in black-box settings, where no information about the model is released except its final decision. Such decision-based attacks usually require lots of queries, while real-world image recognition systems might actually restrict the number of queries. In this paper, we propose qFool, a novel decision-based attack algorithm that can generate adversarial examples using a small number of queries. The qFool method can drastically reduce the number of queries compared to previous decision-based attacks while reaching the same quality of adversarial examples. We also enhance our method by constraining adversarial perturbations in low-frequency subspace, which can make qFool even more computationally efficient. Altogether, we manage to fool commercial image recognition systems with a small number of queries, which demonstrates the actual effectiveness of our new algorithm in practice.
引用
收藏
页码:4889 / 4897
页数:9
相关论文
共 50 条
  • [1] Decision-Based Adversarial Attack with Frequency Mixup
    Li, Xiu-Chuan
    Zhang, Xu-Yao
    Yin, Fei
    Liu, Cheng-Lin
    [J]. IEEE Transactions on Information Forensics and Security, 2022, 17 : 1038 - 1052
  • [2] Decision-Based Adversarial Attack With Frequency Mixup
    Li, Xiu-Chuan
    Zhang, Xu-Yao
    Yin, Fei
    Liu, Cheng-Lin
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2022, 17 : 1038 - 1052
  • [3] PopSkipJump: Decision-Based Attack for Probabilistic Classifiers
    Simon-Gabriel, Carl-Johann
    Sheikh, Noman Ahmed
    Krause, Andreas
    [J]. INTERNATIONAL CONFERENCE ON MACHINE LEARNING, VOL 139, 2021, 139
  • [4] Noncommutative geometry-inspired dirty black holes
    Nicolini, Piero
    Spallucci, Euro
    [J]. CLASSICAL AND QUANTUM GRAVITY, 2010, 27 (01)
  • [5] Triangle Attack: A Query-Efficient Decision-Based Adversarial Attack
    Wang, Xiaosen
    Zhang, Zeliang
    Tong, Kangheng
    Gong, Dihong
    He, Kun
    Li, Zhifeng
    Liu, Andwei
    [J]. COMPUTER VISION - ECCV 2022, PT V, 2022, 13665 : 156 - 174
  • [6] HopSkipJumpAttack: A Query-Efficient Decision-Based Attack
    Chen, Jianbo
    Jordan, Michael, I
    Wainwright, Martin J.
    [J]. 2020 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP 2020), 2020, : 1277 - 1294
  • [7] Noncommutative geometry-inspired rotating black hole in three dimensions
    JUAN MANUEL TEJEIRO
    ALEXIS LARRAÑAGA
    [J]. Pramana, 2012, 78 : 155 - 164
  • [8] Geometry-Inspired Top-k Adversarial Perturbations
    Tursynbek, Nurislam
    Petiushko, Aleksandr
    Oseledets, Ivan
    [J]. 2022 IEEE WINTER CONFERENCE ON APPLICATIONS OF COMPUTER VISION (WACV 2022), 2022, : 4059 - 4068
  • [9] FaDec: A Fast Decision-based Attack for Adversarial Machine Learning
    Khalid, Faiq
    Ali, Hassan
    Hanif, Muhammad Abdullah
    Rehman, Semeen
    Ahmed, Rehan
    Shafique, Muhammad
    [J]. 2020 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS (IJCNN), 2020,
  • [10] Noncommutative geometry-inspired rotating black hole in three dimensions
    Manuel Tejeiro, Juan
    Larranaga, Alexis
    [J]. PRAMANA-JOURNAL OF PHYSICS, 2012, 78 (01): : 155 - 164