How stealthy is stealthy? Studying the Efficacy of Black-Box Adversarial Attacks in the Real World

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Panebianco, Francesco, D'Onghia, Mario, Carminati, Stefano Zanero aand Michele
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866910990103216128
author Panebianco, Francesco
D'Onghia, Mario
Carminati, Stefano Zanero aand Michele
author_facet Panebianco, Francesco
D'Onghia, Mario
Carminati, Stefano Zanero aand Michele
contents Deep learning systems, critical in domains like autonomous vehicles, are vulnerable to adversarial examples (crafted inputs designed to mislead classifiers). This study investigates black-box adversarial attacks in computer vision. This is a realistic scenario, where attackers have query-only access to the target model. Three properties are introduced to evaluate attack feasibility: robustness to compression, stealthiness to automatic detection, and stealthiness to human inspection. State-of-the-Art methods tend to prioritize one criterion at the expense of others. We propose ECLIPSE, a novel attack method employing Gaussian blurring on sampled gradients and a local surrogate model. Comprehensive experiments on a public dataset highlight ECLIPSE's advantages, demonstrating its contribution to the trade-off between the three properties.
format Preprint
id arxiv_https___arxiv_org_abs_2506_05382
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle How stealthy is stealthy? Studying the Efficacy of Black-Box Adversarial Attacks in the Real World
Panebianco, Francesco
D'Onghia, Mario
Carminati, Stefano Zanero aand Michele
Cryptography and Security
Artificial Intelligence
Deep learning systems, critical in domains like autonomous vehicles, are vulnerable to adversarial examples (crafted inputs designed to mislead classifiers). This study investigates black-box adversarial attacks in computer vision. This is a realistic scenario, where attackers have query-only access to the target model. Three properties are introduced to evaluate attack feasibility: robustness to compression, stealthiness to automatic detection, and stealthiness to human inspection. State-of-the-Art methods tend to prioritize one criterion at the expense of others. We propose ECLIPSE, a novel attack method employing Gaussian blurring on sampled gradients and a local surrogate model. Comprehensive experiments on a public dataset highlight ECLIPSE's advantages, demonstrating its contribution to the trade-off between the three properties.
title How stealthy is stealthy? Studying the Efficacy of Black-Box Adversarial Attacks in the Real World
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2506.05382