Distributed Black-box Attack: Do Not Overestimate Black-box Attacks
Fuente:
arXiv
Guardado en:
| Autores principales: | , , |
|---|---|
| Formato: | Preprint |
| Publicado: |
2022
|
| Materias: | |
| Acceso en línea: | |
| Etiquetas: |
Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
|
| _version_ | 1866910878274682880 |
|---|---|
| author | Wu, Han Rowlands, Sareh Wahlstrom, Johan |
| author_facet | Wu, Han Rowlands, Sareh Wahlstrom, Johan |
| contents | As cloud computing becomes pervasive, deep learning models are deployed on cloud servers and then provided as APIs to end users. However, black-box adversarial attacks can fool image classification models without access to model structure and weights. Recent studies have reported attack success rates of over 95% with fewer than 1,000 queries. Then the question arises: whether black-box attacks have become a real threat against cloud APIs? To shed some light on this, our research indicates that black-box attacks are not as effective against cloud APIs as proposed in research papers due to several common mistakes that overestimate the efficiency of black-box attacks. To avoid similar mistakes, we conduct black-box attacks directly on cloud APIs rather than local models. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2210_16371 |
| institution | arXiv |
| publishDate | 2022 |
| record_format | arxiv |
| spellingShingle | Distributed Black-box Attack: Do Not Overestimate Black-box Attacks Wu, Han Rowlands, Sareh Wahlstrom, Johan Machine Learning As cloud computing becomes pervasive, deep learning models are deployed on cloud servers and then provided as APIs to end users. However, black-box adversarial attacks can fool image classification models without access to model structure and weights. Recent studies have reported attack success rates of over 95% with fewer than 1,000 queries. Then the question arises: whether black-box attacks have become a real threat against cloud APIs? To shed some light on this, our research indicates that black-box attacks are not as effective against cloud APIs as proposed in research papers due to several common mistakes that overestimate the efficiency of black-box attacks. To avoid similar mistakes, we conduct black-box attacks directly on cloud APIs rather than local models. |
| title | Distributed Black-box Attack: Do Not Overestimate Black-box Attacks |
| topic | Machine Learning |
| url | https://arxiv.org/abs/2210.16371 |