BB-Patch: BlackBox Adversarial Patch-Attack using Zeroth-Order Optimization

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Kumar, Satyadwyoom, Gupta, Saurabh, Buduru, Arun Balaji
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866917662543577088
author Kumar, Satyadwyoom
Gupta, Saurabh
Buduru, Arun Balaji
author_facet Kumar, Satyadwyoom
Gupta, Saurabh
Buduru, Arun Balaji
contents Deep Learning has become popular due to its vast applications in almost all domains. However, models trained using deep learning are prone to failure for adversarial samples and carry a considerable risk in sensitive applications. Most of these adversarial attack strategies assume that the adversary has access to the training data, the model parameters, and the input during deployment, hence, focus on perturbing the pixel level information present in the input image. Adversarial Patches were introduced to the community which helped in bringing out the vulnerability of deep learning models in a much more pragmatic manner but here the attacker has a white-box access to the model parameters. Recently, there has been an attempt to develop these adversarial attacks using black-box techniques. However, certain assumptions such as availability large training data is not valid for a real-life scenarios. In a real-life scenario, the attacker can only assume the type of model architecture used from a select list of state-of-the-art architectures while having access to only a subset of input dataset. Hence, we propose an black-box adversarial attack strategy that produces adversarial patches which can be applied anywhere in the input image to perform an adversarial attack.
format Preprint
id arxiv_https___arxiv_org_abs_2405_06049
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle BB-Patch: BlackBox Adversarial Patch-Attack using Zeroth-Order Optimization
Kumar, Satyadwyoom
Gupta, Saurabh
Buduru, Arun Balaji
Computer Vision and Pattern Recognition
Cryptography and Security
Machine Learning
Deep Learning has become popular due to its vast applications in almost all domains. However, models trained using deep learning are prone to failure for adversarial samples and carry a considerable risk in sensitive applications. Most of these adversarial attack strategies assume that the adversary has access to the training data, the model parameters, and the input during deployment, hence, focus on perturbing the pixel level information present in the input image. Adversarial Patches were introduced to the community which helped in bringing out the vulnerability of deep learning models in a much more pragmatic manner but here the attacker has a white-box access to the model parameters. Recently, there has been an attempt to develop these adversarial attacks using black-box techniques. However, certain assumptions such as availability large training data is not valid for a real-life scenarios. In a real-life scenario, the attacker can only assume the type of model architecture used from a select list of state-of-the-art architectures while having access to only a subset of input dataset. Hence, we propose an black-box adversarial attack strategy that produces adversarial patches which can be applied anywhere in the input image to perform an adversarial attack.
title BB-Patch: BlackBox Adversarial Patch-Attack using Zeroth-Order Optimization
topic Computer Vision and Pattern Recognition
Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2405.06049