Quantization Aware Attack: Enhancing Transferable Adversarial Attacks by Model Quantization

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Yang, Yulong, Lin, Chenhao, Li, Qian, Zhao, Zhengyu, Fan, Haoran, Zhou, Dawei, Wang, Nannan, Liu, Tongliang, Shen, Chao
Format: Preprint
Published: 2023
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909109948776448
author Yang, Yulong
Lin, Chenhao
Li, Qian
Zhao, Zhengyu
Fan, Haoran
Zhou, Dawei
Wang, Nannan
Liu, Tongliang
Shen, Chao
author_facet Yang, Yulong
Lin, Chenhao
Li, Qian
Zhao, Zhengyu
Fan, Haoran
Zhou, Dawei
Wang, Nannan
Liu, Tongliang
Shen, Chao
contents Quantized neural networks (QNNs) have received increasing attention in resource-constrained scenarios due to their exceptional generalizability. However, their robustness against realistic black-box adversarial attacks has not been extensively studied. In this scenario, adversarial transferability is pursued across QNNs with different quantization bitwidths, which particularly involve unknown architectures and defense methods. Previous studies claim that transferability is difficult to achieve across QNNs with different bitwidths on the condition that they share the same architecture. However, we discover that under different architectures, transferability can be largely improved by using a QNN quantized with an extremely low bitwidth as the substitute model. We further improve the attack transferability by proposing \textit{quantization aware attack} (QAA), which fine-tunes a QNN substitute model with a multiple-bitwidth training objective. In particular, we demonstrate that QAA addresses the two issues that are commonly known to hinder transferability: 1) quantization shifts and 2) gradient misalignments. Extensive experimental results validate the high transferability of the QAA to diverse target models. For instance, when adopting the ResNet-34 substitute model on ImageNet, QAA outperforms the current best attack in attacking standardly trained DNNs, adversarially trained DNNs, and QNNs with varied bitwidths by 4.3\% $\sim$ 20.9\%, 8.7\% $\sim$ 15.5\%, and 2.6\% $\sim$ 31.1\% (absolute), respectively. In addition, QAA is efficient since it only takes one epoch for fine-tuning. In the end, we empirically explain the effectiveness of QAA from the view of the loss landscape. Our code is available at https://github.com/yyl-github-1896/QAA/
format Preprint
id arxiv_https___arxiv_org_abs_2305_05875
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Quantization Aware Attack: Enhancing Transferable Adversarial Attacks by Model Quantization
Yang, Yulong
Lin, Chenhao
Li, Qian
Zhao, Zhengyu
Fan, Haoran
Zhou, Dawei
Wang, Nannan
Liu, Tongliang
Shen, Chao
Cryptography and Security
Quantized neural networks (QNNs) have received increasing attention in resource-constrained scenarios due to their exceptional generalizability. However, their robustness against realistic black-box adversarial attacks has not been extensively studied. In this scenario, adversarial transferability is pursued across QNNs with different quantization bitwidths, which particularly involve unknown architectures and defense methods. Previous studies claim that transferability is difficult to achieve across QNNs with different bitwidths on the condition that they share the same architecture. However, we discover that under different architectures, transferability can be largely improved by using a QNN quantized with an extremely low bitwidth as the substitute model. We further improve the attack transferability by proposing \textit{quantization aware attack} (QAA), which fine-tunes a QNN substitute model with a multiple-bitwidth training objective. In particular, we demonstrate that QAA addresses the two issues that are commonly known to hinder transferability: 1) quantization shifts and 2) gradient misalignments. Extensive experimental results validate the high transferability of the QAA to diverse target models. For instance, when adopting the ResNet-34 substitute model on ImageNet, QAA outperforms the current best attack in attacking standardly trained DNNs, adversarially trained DNNs, and QNNs with varied bitwidths by 4.3\% $\sim$ 20.9\%, 8.7\% $\sim$ 15.5\%, and 2.6\% $\sim$ 31.1\% (absolute), respectively. In addition, QAA is efficient since it only takes one epoch for fine-tuning. In the end, we empirically explain the effectiveness of QAA from the view of the loss landscape. Our code is available at https://github.com/yyl-github-1896/QAA/
title Quantization Aware Attack: Enhancing Transferable Adversarial Attacks by Model Quantization
topic Cryptography and Security
url https://arxiv.org/abs/2305.05875