Hard-label based Small Query Black-box Adversarial Attack

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Park, Jeonghwan, Miller, Paul, McLaughlin, Niall
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866929270510583808
author Park, Jeonghwan
Miller, Paul
McLaughlin, Niall
author_facet Park, Jeonghwan
Miller, Paul
McLaughlin, Niall
contents We consider the hard label based black box adversarial attack setting which solely observes predicted classes from the target model. Most of the attack methods in this setting suffer from impractical number of queries required to achieve a successful attack. One approach to tackle this drawback is utilising the adversarial transferability between white box surrogate models and black box target model. However, the majority of the methods adopting this approach are soft label based to take the full advantage of zeroth order optimisation. Unlike mainstream methods, we propose a new practical setting of hard label based attack with an optimisation process guided by a pretrained surrogate model. Experiments show the proposed method significantly improves the query efficiency of the hard label based black-box attack across various target model architectures. We find the proposed method achieves approximately 5 times higher attack success rate compared to the benchmarks, especially at the small query budgets as 100 and 250.
format Preprint
id arxiv_https___arxiv_org_abs_2403_06014
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Hard-label based Small Query Black-box Adversarial Attack
Park, Jeonghwan
Miller, Paul
McLaughlin, Niall
Machine Learning
Artificial Intelligence
Computer Vision and Pattern Recognition
We consider the hard label based black box adversarial attack setting which solely observes predicted classes from the target model. Most of the attack methods in this setting suffer from impractical number of queries required to achieve a successful attack. One approach to tackle this drawback is utilising the adversarial transferability between white box surrogate models and black box target model. However, the majority of the methods adopting this approach are soft label based to take the full advantage of zeroth order optimisation. Unlike mainstream methods, we propose a new practical setting of hard label based attack with an optimisation process guided by a pretrained surrogate model. Experiments show the proposed method significantly improves the query efficiency of the hard label based black-box attack across various target model architectures. We find the proposed method achieves approximately 5 times higher attack success rate compared to the benchmarks, especially at the small query budgets as 100 and 250.
title Hard-label based Small Query Black-box Adversarial Attack
topic Machine Learning
Artificial Intelligence
Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2403.06014