DAIR: A Query-Efficient Decision-based Attack on Image Retrieval Systems
Mingyang Chen, Junda Lu, Yi Wang, Jianbin Qin, Wei Wang
Abstract
There is an increasing interest in studying adversarial attacks on image retrieval systems. However, most of the existing attack methods are based on the white-box setting, where the attackers have access to all the model and database details, which is a strong assumption for practical attacks. The generic transfer-based attack also requires substantial resources yet the effect was shown to be unreliable. In this paper, we make the first attempt in proposing a query-efficient decision-based attack framework for the image retrieval (DAIR) to completely subvert the top-K retrieval results with human imperceptible perturbations. We propose an optimization-based method with a smoothed utility function to overcome the challenging discrete nature of the problem. To further improve the query efficiency, we propose a novel sampling method that can achieve the transferability between the surrogate and the target model efficiently. Our comprehensive experimental evaluation on the benchmark datasets shows that our DAIR method outperforms significantly the state-of-the-art decision-based methods. We also demonstrate that real image retrieval engines (Bing Visual Search and Face++ engines) can be attacked successfully with only several hundreds of queries.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 15a3fb4d-7256-4c72-bc6d-e36f11784698Cited by top-tier papers6
- Topic-oriented Adversarial Attacks against Black-box Neural Ranking ModelsYu-An Liu, Ruqing Zhang, Jiafeng Guo, Maarten de Rijke et al.SIGIR 2023 · 20 citations
- Once and for All: Universal Transferable Adversarial Perturbation against Deep Hashing-Based Facial Image RetrievalLong Tang, Dengpan Ye, Yunna Lv, Chuanxi Chen et al.AAAI 2024 · 13 citations
- HUANG: A Robust Diffusion Model-based Targeted Adversarial Attack Against Deep Hashing RetrievalChihan Huang, Xiaobo ShenAAAI 2025 · 5 citations
- Collapse-Aware Triplet Decoupling for Adversarially Robust Image RetrievalQiwei Tian, Chenhao Lin, Zhengyu Zhao, Qian Li et al.ICML 2024 · 3 citations
- Toward Understanding Adversarial Distillation: Why Robust Teachers FailHongsin Lee, Hye Won ChungICML 2026
Related papers
- QAIR: Practical Query-Efficient Black-Box Attacks for Image RetrievalXiaodan Li, Jinfeng Li, Yuefeng Chen, Shaokai Ye et al.CVPR 2021
- Transferability of White-box Perturbations: Query-Efficient Adversarial Attacks against Commercial DNN ServicesMeng Shen, Changyue Li, Qi Li, Hao Lu et al.USENIX Security 2024 · 8 citations
- Unsupervised Corpus Poisoning Attacks in Continuous Space for Dense RetrievalYongkang Li, Panagiotis Eustratiadis, Simon Lupart, Evangelos KanoulasSIGIR 2025 · 3 citations
- Universal Perturbation Attack Against Image RetrievalJie Li, Rongrong Ji, Hong Liu, Xiaopeng Hong et al.ICCV 2019 · 115 citations
- Black-Box Adversarial Attack with Transferable Model-based EmbeddingZhichao Huang, Tong ZhangICLR 2020 · 131 citations
