Aha! Adaptive History-driven Attack for Decision-based Black-box Models

被引:4
|
作者
Li, Jie [1 ]
Ji, Rongrong [1 ,2 ,4 ]
Chen, Peixian [1 ,6 ]
Zhang, Baochang [3 ]
Hong, Xiaopeng [5 ]
Zhang, Ruixin [6 ]
Li, Shaoxin [6 ]
Li, Jilin [6 ]
Huang, Feiyue [6 ]
Wu, Yongjian [6 ]
机构
[1] Xiamen Univ, MAC Lab, Sch Informat, Xiamen, Peoples R China
[2] Peng Cheng Lab, Xiamen, Peoples R China
[3] Beihang Univ, Beijing, Peoples R China
[4] Xiamen Univ, Inst Artificial Intelligence, Xiamen, Peoples R China
[5] Xi An Jiao Tong Univ, Xian, Peoples R China
[6] Tencent, Youtu Lab, Shenzhen, Peoples R China
基金
中国国家自然科学基金;
关键词
D O I
10.1109/ICCV48922.2021.01586
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
The decision-based black-box attack means to craft adversarial examples with only the top-1 label of the victim model available. A common practice is to start from a large perturbation and then iteratively reduce it with a deterministic direction and a random one while keeping it adversarial. The limited information obtained from each query and inefficient direction sampling impede attack efficiency, making it hard to obtain a small enough perturbation within a limited number of queries. To tackle this problem, we propose a novel attack method termed Adaptive History-driven Attack (AHA) which gathers information from all historical queries as the prior for current sampling. Moreover, to balance between the deterministic direction and the random one, we dynamically adjust the coefficient according to the ratio of the actual magnitude reduction to the expected one. Such a strategy improves the success rate of queries during optimization, letting adversarial examples move swiftly along the decision boundary. Our method can also integrate with subspace optimization like dimension reduction to further improve efficiency. Extensive experiments on both ImageNet and CelebA datasets demonstrate that our method achieves at least 24.3% lower magnitude of perturbation on average with the same number of queries. Finally, we prove the practical potential of our method by evaluating it on popular defense methods and a real-world system provided by MEGVII Face++.
引用
收藏
页码:16148 / 16157
页数:10
相关论文
共 50 条
  • [1] Perception-Driven Imperceptible Adversarial Attack Against Decision-Based Black-Box Models
    Zhang, Shenyi
    Zheng, Baolin
    Jiang, Peipei
    Zhao, Lingchen
    Shen, Chao
    Wang, Qian
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 3164 - 3177
  • [2] Boosting Decision-Based Black-Box Adversarial Attack with Gradient Priors
    Liu, Han
    Huang, Xingshuo
    Zhang, Xiaotong
    Li, Qimai
    Ma, Fenglong
    Wang, Wei
    Chen, Hongyang
    Yu, Hong
    Zhang, Xianchao
    PROCEEDINGS OF THE THIRTY-SECOND INTERNATIONAL JOINT CONFERENCE ON ARTIFICIAL INTELLIGENCE, IJCAI 2023, 2023, : 1195 - 1203
  • [3] Query-Efficient Decision-Based Black-Box Patch Attack
    Chen, Zhaoyu
    Li, Bo
    Wu, Shuang
    Ding, Shouhong
    Zhang, Wenqiang
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2023, 18 : 5522 - 5536
  • [4] FastTextDodger: Decision-Based Adversarial Attack Against Black-Box NLP Models With Extremely High Efficiency
    Hu, Xiaoxue
    Liu, Geling
    Zheng, Baolin
    Zhao, Lingchen
    Wang, Qian
    Zhang, Yufei
    Du, Minxin
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 2398 - 2411
  • [5] MalAder: Decision-Based Black-Box Attack Against API Sequence Based Malware Detectors
    Chen, Xiaohui
    Cui, Lei
    Wen, Hui
    Li, Zhi
    Zhu, Hongsong
    Hao, Zhiyu
    Sun, Limin
    2023 53RD ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS, DSN, 2023, : 165 - 178
  • [6] ROBUST DECISION-BASED BLACK-BOX ADVERSARIAL ATTACK VIA COARSE-TO-FINE RANDOM SEARCH
    Kim, Byeong Cheon
    Yu, Youngjoon
    Ro, Yong Man
    2021 IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING (ICIP), 2021, : 3048 - 3052
  • [7] Efficient Decision-based Black-box Adversarial Attacks on Face Recognition
    Dong, Yinpeng
    Su, Hang
    Wu, Baoyuan
    Li, Zhifeng
    Liu, Wei
    Zhang, Tong
    Zhu, Jun
    2019 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR 2019), 2019, : 7706 - 7714
  • [8] Efficient Decision-based Black-box Patch Attacks on Video Recognition
    Jiang, Kaixun
    Chen, Zhaoyu
    Huang, Hao
    Wang, Jiafeng
    Yang, Dingkang
    Li, Bo
    Wang, Yan
    Zhang, Wenqiang
    2023 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION, ICCV, 2023, : 4356 - 4366
  • [9] Decision-based Black-box Attack Against Vision Transformers via Patch-wise Adversarial Removal
    Shi, Yucheng
    Han, Yahong
    Tan, Yu-an
    Kuang, Xiaohui
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 35 (NEURIPS 2022), 2022,
  • [10] Adversarial Eigen Attack on Black-Box Models
    Zhou, Linjun
    Cui, Peng
    Zhang, Xingxuan
    Jiang, Yinan
    Yang, Shiqiang
    2022 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR 2022), 2022, : 15233 - 15241