Practical Black-Box Attacks on Deep Neural Networks Using Efficient Query Mechanisms

被引:119
|
作者
Bhagoji, Arjun Nitin [1 ,2 ]
He, Warren [2 ]
Li, Bo [3 ]
Song, Dawn [2 ]
机构
[1] Princeton Univ, Princeton, NJ 08544 USA
[2] Univ Calif Berkeley, Berkeley, CA 94720 USA
[3] Univ Illinois, Champaign, IL USA
来源
关键词
Deep neural networks; Image classification; Adversarial examples; Black-box attacks;
D O I
10.1007/978-3-030-01258-8_10
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Existing black-box attacks on deep neural networks (DNNs) have largely focused on transferability, where an adversarial instance generated for a locally trained model can "transfer" to attack other learning models. In this paper, we propose novel Gradient Estimation black-box attacks for adversaries with query access to the target model's class probabilities, which do not rely on transferability. We also propose strategies to decouple the number of queries required to generate each adversarial sample from the dimensionality of the input. An iterative variant of our attack achieves close to 100% attack success rates for both targeted and untargeted attacks on DNNs. We carry out a thorough comparative evaluation of black-box attacks and show that Gradient Estimation attacks achieve attack success rates similar to state-of-the-art white-box attacks on the MNIST and CIFAR-10 datasets. We also apply the Gradient Estimation attacks successfully against real-world classifiers hosted by Clarifai. Further, we evaluate black-box attacks against state-of-the-art defenses based on adversarial training and show that the Gradient Estimation attacks are very effective even against these defenses.
引用
收藏
页码:158 / 174
页数:17
相关论文
共 50 条
  • [1] Query efficient black-box adversarial attack on deep neural networks
    Bai, Yang
    Wang, Yisen
    Zeng, Yuyuan
    Jiang, Yong
    Xia, Shu-Tao
    [J]. PATTERN RECOGNITION, 2023, 133
  • [2] QAIR: Practical Query-efficient Black-Box Attacks for Image Retrieval
    Li, Xiaodan
    Li, Jinfeng
    Chen, Yuefeng
    Ye, Shaokai
    He, Yuan
    Wang, Shuhui
    Su, Hang
    Xue, Hui
    [J]. 2021 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION, CVPR 2021, 2021, : 3329 - 3338
  • [3] Simple Black-Box Adversarial Attacks on Deep Neural Networks
    Narodytska, Nina
    Kasiviswanathan, Shiva
    [J]. 2017 IEEE CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION WORKSHOPS (CVPRW), 2017, : 1310 - 1318
  • [4] Towards Lightweight Black-Box Attacks Against Deep Neural Networks
    Sun, Chenghao
    Zhang, Yonggang
    Wan Chaoqun
    Wang, Qizhou
    Li, Ya
    Liu, Tongliang
    Han, Bo
    Tian, Xinmei
    [J]. ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 35 (NEURIPS 2022), 2022,
  • [5] Black-Box Testing of Deep Neural Networks
    Byun, Taejoon
    Rayadurgam, Sanjai
    Heimdahl, Mats P. E.
    [J]. 2021 IEEE 32ND INTERNATIONAL SYMPOSIUM ON SOFTWARE RELIABILITY ENGINEERING (ISSRE 2021), 2021, : 309 - 320
  • [6] Blacklight: Scalable Defense for Neural Networks against Query-Based Black-Box Attacks
    Li, Huiying
    Shan, Shawn
    Wenger, Emily
    Zhang, Jiayun
    Zheng, Haitao
    Zhao, Ben Y.
    [J]. PROCEEDINGS OF THE 31ST USENIX SECURITY SYMPOSIUM, 2022, : 2117 - 2134
  • [7] Evaluating and Enhancing the Robustness of Sustainable Neural Relationship Classifiers Using Query-Efficient Black-Box Adversarial Attacks
    Haq, Ijaz Ul
    Khan, Zahid Younas
    Ahmad, Arshad
    Hayat, Bashir
    Khan, Asif
    Lee, Ye-Eun
    Kim, Ki-Il
    [J]. SUSTAINABILITY, 2021, 13 (11)
  • [8] NeuralBO: A black-box optimization algorithm using deep neural networks
    Dat, Phan-Trong
    Hung, Tran-The
    Gupta, Sunil
    [J]. NEUROCOMPUTING, 2023, 559
  • [9] Query-Efficient Hard-Label Black-Box Attacks Using Biased Sampling
    Liu, Sijia
    Sun, Jian
    Li, Jun
    [J]. 2020 CHINESE AUTOMATION CONGRESS (CAC 2020), 2020, : 3872 - 3877
  • [10] AdverseGen: A Practical Tool for Generating Adversarial Examples to Deep Neural Networks Using Black-Box Approaches
    Zhang, Keyuan
    Wu, Kaiyue
    Chen, Siyu
    Zhao, Yunce
    Yao, Xin
    [J]. ARTIFICIAL INTELLIGENCE XXXVIII, 2021, 13101 : 313 - 326