Efficient Black-box Adversarial Attacks via Bayesian Optimization Guided by a Function Prior
Shuyu Cheng, Yibo Miao, Yinpeng Dong, Xiao Yang, Xiao-Shan Gao, Jun Zhu
Abstract
This paper studies the challenging black-box adversarial attack that aims to generate adversarial examples against a black-box model by only using output feedback of the model to input queries. Some previous methods improve the query efficiency by incorporating the gradient of a surrogate white-box model into query-based attacks due to the adversarial transferability. However, the localized gradient is not informative enough, making these methods still query-intensive. In this paper, we propose a Prior-guided Bayesian Optimization (P-BO) algorithm that leverages the surrogate model as a global function prior in black-box adversarial attacks. As the surrogate model contains rich prior information of the black-box one, P-BO models the attack objective with a Gaussian process whose mean function is initialized as the surrogate model's loss. Our theoretical analysis on the regret bound indicates that the performance of P-BO may be affected by a bad prior. Therefore, we further propose an adaptive integration strategy to automatically adjust a coefficient on the function prior by minimizing the regret bound. Extensive experiments on image classifiers and large vision-language models demonstrate the superiority of the proposed algorithm in reducing queries and improving attack success rates compared with the state-of-the-art black-box attacks. Code is available at https://github.com/ yibo-miao/PBO-Attack .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 24f4188e-8daa-4c64-a26d-7fea29f37f54Cited by top-tier papers7
- Improving Robustness of 3D Point Cloud Recognition from a Fourier PerspectiveYibo Miao, Yinpeng Dong, Jinlai Zhang, Lijia Yu et al.NeurIPS 2024 · 15 citations
- Red-Teaming Text-to-Image Systems by Rule-based Preference ModelingYichuan Cao, Yibo Miao, Xiao-Shan Gao, Yinpeng DongNeurIPS 2025 · 8 citations
- Time Is All It Takes: Spike-Retiming Attacks on Event-Driven Spiking Neural NetworksYi Yu, Qixin Zhang, Shuhan Ye, Xun Lin et al.ICLR 2026 · 8 citations
- Why Do Unlearnable Examples Work: A Novel Perspective of Mutual InformationYifan Zhu, Yibo Miao, Yinpeng Dong, Xiao-Shan GaoICLR 2026 · 3 citations
- VLMInferSlow: Evaluating the Efficiency Robustness of Large Vision-Language Models as a ServiceXiasi Wang, Tianliang Yao, Simin Chen, Runqi Wang et al.ACL 2025 · 3 citations
Builds on29
- Learning Transferable Visual Models From Natural Language SupervisionAlec Radford, Jong Wook Kim, Chris Hallacy, Aditya Ramesh et al.ICML 2021 · 47,906 citations
- Swin Transformer: Hierarchical Vision Transformer using Shifted WindowsZe Liu, Yutong Lin, Yue Cao, Han Hu et al.ICCV 2021 · 31,683 citations
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn et al.ICLR 2021 · 21,477 citations
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- InstructBLIP: Towards General-purpose Vision-Language Models with Instruction TuningWenliang Dai, Junnan Li, Dongxu Li, Anthony Meng Huat Tiong et al.NeurIPS 2023 · 4,013 citations
Related papers
- Boosting Ray Search Procedure of Hard-label Attacks with Transfer-based PriorsChen Ma, Xinjie Xu, Shuyu Cheng, Qi XuanICLR 2025
- BayesOpt Adversarial AttackBinxin Ru, Adam D. Cobb, Arno Blaas, Yarin GalICLR 2020 · 85 citations
- Blackbox Attacks via Surrogate Ensemble SearchZikui Cai, Chengyu Song, Srikanth V. Krishnamurthy, Amit Roy-Chowdhury et al.NeurIPS 2022 · 32 citations
- Simple and Efficient Hard Label Black-box Adversarial Attacks in Low Query Budget RegimesSatya Narayan Shukla, Anit Kumar Sahu, Devin Willmott, J. Zico KolterKDD 2021 · 24 citations
- Black-Box Adversarial Attack with Transferable Model-based EmbeddingZhichao Huang, Tong ZhangICLR 2020 · 131 citations
