Boosting Ray Search Procedure of Hard-label Attacks with Transfer-based Priors

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Ma, Chen, Xu, Xinjie, Cheng, Shuyu, Xuan, Qi
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866911073012023296
author Ma, Chen
Xu, Xinjie
Cheng, Shuyu
Xuan, Qi
author_facet Ma, Chen
Xu, Xinjie
Cheng, Shuyu
Xuan, Qi
contents One of the most practical and challenging types of black-box adversarial attacks is the hard-label attack, where only the top-1 predicted label is available. One effective approach is to search for the optimal ray direction from the benign image that minimizes the $\ell_p$-norm distance to the adversarial region. The unique advantage of this approach is that it transforms the hard-label attack into a continuous optimization problem. The objective function value is the ray's radius, which can be obtained via binary search at a high query cost. Existing methods use a "sign trick" in gradient estimation to reduce the number of queries. In this paper, we theoretically analyze the quality of this gradient estimation and propose a novel prior-guided approach to improve ray search efficiency both theoretically and empirically. Specifically, we utilize the transfer-based priors from surrogate models, and our gradient estimators appropriately integrate them by approximating the projection of the true gradient onto the subspace spanned by these priors and random directions, in a query-efficient manner. We theoretically derive the expected cosine similarities between the obtained gradient estimators and the true gradient, and demonstrate the improvement achieved by incorporating priors. Extensive experiments on the ImageNet and CIFAR-10 datasets show that our approach significantly outperforms 11 state-of-the-art methods in terms of query efficiency.
format Preprint
id arxiv_https___arxiv_org_abs_2507_17577
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Boosting Ray Search Procedure of Hard-label Attacks with Transfer-based Priors
Ma, Chen
Xu, Xinjie
Cheng, Shuyu
Xuan, Qi
Computer Vision and Pattern Recognition
Cryptography and Security
Machine Learning
I.2.6; I.5.1; G.1.6
One of the most practical and challenging types of black-box adversarial attacks is the hard-label attack, where only the top-1 predicted label is available. One effective approach is to search for the optimal ray direction from the benign image that minimizes the $\ell_p$-norm distance to the adversarial region. The unique advantage of this approach is that it transforms the hard-label attack into a continuous optimization problem. The objective function value is the ray's radius, which can be obtained via binary search at a high query cost. Existing methods use a "sign trick" in gradient estimation to reduce the number of queries. In this paper, we theoretically analyze the quality of this gradient estimation and propose a novel prior-guided approach to improve ray search efficiency both theoretically and empirically. Specifically, we utilize the transfer-based priors from surrogate models, and our gradient estimators appropriately integrate them by approximating the projection of the true gradient onto the subspace spanned by these priors and random directions, in a query-efficient manner. We theoretically derive the expected cosine similarities between the obtained gradient estimators and the true gradient, and demonstrate the improvement achieved by incorporating priors. Extensive experiments on the ImageNet and CIFAR-10 datasets show that our approach significantly outperforms 11 state-of-the-art methods in terms of query efficiency.
title Boosting Ray Search Procedure of Hard-label Attacks with Transfer-based Priors
topic Computer Vision and Pattern Recognition
Cryptography and Security
Machine Learning
I.2.6; I.5.1; G.1.6
url https://arxiv.org/abs/2507.17577