Data-Free Adversarial Perturbations for Practical Black-Box Attack

被引:7
|
作者
Huan, Zhaoxin [1 ,2 ]
Wang, Yulong [2 ,3 ]
Zhang, Xiaolu [2 ]
Shang, Lin [1 ]
Fu, Chilin [2 ]
Zhou, Jun [2 ]
机构
[1] Nanjing Univ, Dept Comp Sci & Technol, State Key Lab Novel Software Technol, Nanjing, Peoples R China
[2] Ant Financial Serv Grp, Hangzhou, Peoples R China
[3] Tsinghua Univ, Dept Comp Sci & Technol, Beijing, Peoples R China
基金
中国国家自然科学基金;
关键词
Adversarial machine learning; Black-box adversarial perturbations;
D O I
10.1007/978-3-030-47436-2_10
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Neural networks are vulnerable to adversarial examples, which are malicious inputs crafted to fool pre-trained models. Adversarial examples often exhibit black-box attacking transferability, which allows that adversarial examples crafted for one model can fool another model. However, existing black-box attack methods require samples from the training data distribution to improve the transferability of adversarial examples across different models. Because of the data dependence, fooling ability of adversarial perturbations is only applicable when training data are accessible. In this paper, we present a data-free method for crafting adversarial perturbations that can fool a target model without any knowledge about the training data distribution. In the practical setting of black-box attack scenario where attackers do not have access to target models and training data, our method achieves high fooling rates on target models and outperforms other universal adversarial perturbation methods. Our method empirically shows that current deep learning models are still at a risk even when the attackers do not have access to training data.
引用
收藏
页码:127 / 138
页数:12
相关论文
共 50 条
  • [1] Data-free Universal Adversarial Perturbation and Black-box Attack
    Zhang, Chaoning
    Benz, Philipp
    Karjauv, Adil
    Kweon, In So
    [J]. 2021 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2021), 2021, : 7848 - 7857
  • [2] DFDS: Data-Free Dual Substitutes Hard-Label Black-Box Adversarial Attack
    Jiang, Shuliang
    He, Yusheng
    Zhang, Rui
    Kang, Zi
    Xia, Hui
    [J]. KNOWLEDGE SCIENCE, ENGINEERING AND MANAGEMENT, PT III, KSEM 2024, 2024, 14886 : 274 - 285
  • [3] DST: Dynamic Substitute Training for Data-free Black-box Attack
    Wang, Wenxuan
    Qian, Xuelin
    Fu, Yanwei
    Xue, Xiangyang
    [J]. 2022 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2022, : 14341 - 14350
  • [4] Towards Efficient Data Free Black-box Adversarial Attack
    Zhang, Jie
    Li, Bo
    Xu, Jianghe
    Wu, Shuang
    Ding, Shouhong
    Zhang, Lei
    Wu, Chao
    [J]. 2022 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR 2022), 2022, : 15094 - 15104
  • [5] Effectively Improving Data Diversity of Substitute Training for Data-Free Black-Box Attack
    Wei, Yang
    Ma, Zhuo
    Ma, Zhuoran
    Qin, Zhan
    Liu, Yang
    Xiao, Bin
    Bi, Xiuli
    Ma, Jianfeng
    [J]. IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2024, 21 (04) : 4206 - 4219
  • [6] TSadv: Black-box adversarial attack on time series with local perturbations
    Yang, Wenbo
    Yuan, Jidong
    Wang, Xiaokang
    Zhao, Peixiang
    [J]. ENGINEERING APPLICATIONS OF ARTIFICIAL INTELLIGENCE, 2022, 114
  • [7] TSadv: Black-box adversarial attack on time series with local perturbations
    Yang, Wenbo
    Yuan, Jidong
    Wang, Xiaokang
    Zhao, Peixiang
    [J]. ENGINEERING APPLICATIONS OF ARTIFICIAL INTELLIGENCE, 2022, 114
  • [8] FE-DaST: Fast and effective data-free substitute training for black-box adversarial attacks
    Yu, Mengran
    Sun, Shiliang
    [J]. COMPUTERS & SECURITY, 2022, 113
  • [9] SIMULATOR ATTACK plus FOR BLACK-BOX ADVERSARIAL ATTACK
    Ji, Yimu
    Ding, Jianyu
    Chen, Zhiyu
    Wu, Fei
    Zhang, Chi
    Sun, Yiming
    Sun, Jing
    Liu, Shangdong
    [J]. 2022 IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING, ICIP, 2022, : 636 - 640
  • [10] Amora: Black-box Adversarial Morphing Attack
    Wang, Run
    Juefei-Xu, Felix
    Guo, Qing
    Huang, Yihao
    Xie, Xiaofei
    Ma, Lei
    Liu, Yang
    [J]. MM '20: PROCEEDINGS OF THE 28TH ACM INTERNATIONAL CONFERENCE ON MULTIMEDIA, 2020, : 1376 - 1385