Towards Efficient Data Free Blackbox Adversarial Attack
Jie Zhang, Bo Li, Jianghe Xu, Shuang Wu, Shouhong Ding, Lei Zhang, Chao Wu
Abstract
Classic black-box adversarial attacks can take advantage of transferable adversarial examples generated by a similar substitute model to successfully fool the target model. However, these substitute models need to be trained by target models' training data, which is hard to acquire due to privacy or transmission reasons. Recognizing the limited availability of real data for adversarial queries, recent works proposed to train substitute models in a data-free black-box scenario. However, their generative adversarial networks (GANs) based framework suffers from the convergence failure and the model collapse, resulting in low efficiency. In this paper, by rethinking the collaborative relationship between the generator and the substitute model, we design a novel black-box attack framework. The proposed method can efficiently imitate the target model through a small number of queries and achieve high attack success rate. The comprehensive experiments over six datasets demonstrate the effectiveness of our method against the state-of-the-art attacks. Especially, we conduct both label-only and probability-only attacks on the Microsoft Azure online model, and achieve a 100% attack success rate with only 0.46% query budget of the SOTA method [49].
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers19
- Federated Learning with Label Distribution Skew via Logits CalibrationJie Zhang, Zhiqi Li, Bo Li, Jianghe Xu et al.ICML 2022 · 221 citations
- Delving into the Adversarial Robustness of Federated LearningJie Zhang, Bo Li, Chen Chen, Lingjuan Lyu et al.AAAI 2023 · 62 citations
- CalFAT: Calibrated Federated Adversarial Training with Label SkewnessChen Chen, Yuchen Liu, Xingjun Ma, Lingjuan LyuNeurIPS 2022 · 53 citations
- Attack Can Benefit: An Adversarial Approach to Recognizing Facial Expressions under Noisy AnnotationsJiawen Zheng, Bo Li, Shengchuan Zhang, Shuang Wu et al.AAAI 2023 · 20 citations
- TranSpeech: Speech-to-Speech Translation With Bilateral PerturbationRongjie Huang, Jinglin Liu, Huadai Liu, Yi Ren et al.ICLR 2023 · 17 citations
Builds on11
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- HopSkipJumpAttack: A Query-Efficient Decision-Based AttackJianbo Chen, Michael I. Jordan, Martin J. WainwrightS&P 2020 · 797 citations
- Black-Box Adversarial Attack with Transferable Model-based EmbeddingZhichao Huang, Tong ZhangICLR 2020 · 131 citations
- CMUA-Watermark: A Cross-Model Universal Adversarial Watermark for Combating DeepfakesHao Huang, Yongtao Wang, Zhaoyu Chen, Yuze Zhang et al.AAAI 2022 · 131 citations
- Disentangled High Quality Salient Object DetectionLv Tang, Bo Li, Yijie Zhong, Shouhong Ding et al.ICCV 2021 · 86 citations
Related papers
- DaST: Data-Free Substitute Training for Adversarial AttacksMingyi Zhou, Jing Wu, Yipeng Liu, Shuaicheng Liu et al.CVPR 2020
- DST: Dynamic Substitute Training for Data-free Black-box AttackWenxuan Wang, Xuelin Qian, Yanwei Fu, Xiangyang XueCVPR 2022 · 18 citations
- Delving into Data: Effectively Substitute Training for Black-box AttackWenxuan Wang, Bangjie Yin, Taiping Yao, Li Zhang et al.CVPR 2021
- BayesOpt Adversarial AttackBinxin Ru, Adam D. Cobb, Arno Blaas, Yarin GalICLR 2020 · 85 citations
- KOEnsAttack: Towards Efficient Data-Free Black-Box Adversarial Attacks via Knowledge-Orthogonalized Substitute EnsemblesChaoyong Yang, Jia-Li Yin, Bin Chen, Zhaozhe Hu et al.ICCV 2025
