Distributed Black-box Attack: Do Not Overestimate Black-box Attacks

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Wu, Han, Rowlands, Sareh, Wahlstrom, Johan
Formato: Preprint
Publicado: 2022
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866910878274682880
author Wu, Han
Rowlands, Sareh
Wahlstrom, Johan
author_facet Wu, Han
Rowlands, Sareh
Wahlstrom, Johan
contents As cloud computing becomes pervasive, deep learning models are deployed on cloud servers and then provided as APIs to end users. However, black-box adversarial attacks can fool image classification models without access to model structure and weights. Recent studies have reported attack success rates of over 95% with fewer than 1,000 queries. Then the question arises: whether black-box attacks have become a real threat against cloud APIs? To shed some light on this, our research indicates that black-box attacks are not as effective against cloud APIs as proposed in research papers due to several common mistakes that overestimate the efficiency of black-box attacks. To avoid similar mistakes, we conduct black-box attacks directly on cloud APIs rather than local models.
format Preprint
id arxiv_https___arxiv_org_abs_2210_16371
institution arXiv
publishDate 2022
record_format arxiv
spellingShingle Distributed Black-box Attack: Do Not Overestimate Black-box Attacks
Wu, Han
Rowlands, Sareh
Wahlstrom, Johan
Machine Learning
As cloud computing becomes pervasive, deep learning models are deployed on cloud servers and then provided as APIs to end users. However, black-box adversarial attacks can fool image classification models without access to model structure and weights. Recent studies have reported attack success rates of over 95% with fewer than 1,000 queries. Then the question arises: whether black-box attacks have become a real threat against cloud APIs? To shed some light on this, our research indicates that black-box attacks are not as effective against cloud APIs as proposed in research papers due to several common mistakes that overestimate the efficiency of black-box attacks. To avoid similar mistakes, we conduct black-box attacks directly on cloud APIs rather than local models.
title Distributed Black-box Attack: Do Not Overestimate Black-box Attacks
topic Machine Learning
url https://arxiv.org/abs/2210.16371