Consensus-based optimization for closed-box adversarial attacks and a connection to evolution strategies

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Roith, Tim, Bungert, Leon, Wacker, Philipp
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866913919592824832
author Roith, Tim
Bungert, Leon
Wacker, Philipp
author_facet Roith, Tim
Bungert, Leon
Wacker, Philipp
contents Consensus-based optimization (CBO) has established itself as an efficient gradient-free optimization scheme, with attractive mathematical properties, such as mean-field convergence results for non-convex loss functions. In this work, we study CBO in the context of closed-box adversarial attacks, which are imperceptible input perturbations that aim to fool a classifier, without accessing its gradient. Our contribution is to establish a connection between the so-called consensus hopping as introduced by Riedl et al. and natural evolution strategies (NES) commonly applied in the context of adversarial attacks and to rigorously relate both methods to gradient-based optimization schemes. Beyond that, we provide a comprehensive experimental study that shows that despite the conceptual similarities, CBO can outperform NES and other evolutionary strategies in certain scenarios.
format Preprint
id arxiv_https___arxiv_org_abs_2506_24048
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Consensus-based optimization for closed-box adversarial attacks and a connection to evolution strategies
Roith, Tim
Bungert, Leon
Wacker, Philipp
Optimization and Control
Machine Learning
65K10, 68Q32, 65K15, 90C26
Consensus-based optimization (CBO) has established itself as an efficient gradient-free optimization scheme, with attractive mathematical properties, such as mean-field convergence results for non-convex loss functions. In this work, we study CBO in the context of closed-box adversarial attacks, which are imperceptible input perturbations that aim to fool a classifier, without accessing its gradient. Our contribution is to establish a connection between the so-called consensus hopping as introduced by Riedl et al. and natural evolution strategies (NES) commonly applied in the context of adversarial attacks and to rigorously relate both methods to gradient-based optimization schemes. Beyond that, we provide a comprehensive experimental study that shows that despite the conceptual similarities, CBO can outperform NES and other evolutionary strategies in certain scenarios.
title Consensus-based optimization for closed-box adversarial attacks and a connection to evolution strategies
topic Optimization and Control
Machine Learning
65K10, 68Q32, 65K15, 90C26
url https://arxiv.org/abs/2506.24048