Attacking deep networks with surrogate-based adversarial black-box methods is easy
Nicholas A. Lord, Romain Müller, Luca Bertinetto
Abstract
A recent line of work on black-box adversarial attacks has revived the use of transfer from surrogate models by integrating it into query-based search. However, we find that existing approaches of this type underperform their potential, and can be overly complicated besides. Here, we provide a short and simple algorithm which achieves state-of-the-art results through a search which uses the surrogate network's classscore gradients, with no need for other priors or heuristics. The guiding assumption of the algorithm is that the studied networks are in a fundamental sense learning similar functions, and that a transfer attack from one to the other should thus be fairly "easy". This assumption is validated by the extremely low query counts and failure rates achieved: e.g. an untargeted attack on a VGG-16 ImageNet network using a ResNet-152 as the surrogate yields a median query count of 6 at a success rate of 99.9%. Code is available at https://github.com/fiveai/GFCS .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 43b0b8e6-efba-4db0-850d-e8d786c77c99Cited by top-tier papers4
- Blackbox Attacks via Surrogate Ensemble SearchZikui Cai, Chengyu Song, Srikanth V. Krishnamurthy, Amit Roy-Chowdhury et al.NeurIPS 2022 · 32 citations
- Efficient Black-box Adversarial Attacks via Bayesian Optimization Guided by a Function PriorShuyu Cheng, Yibo Miao, Yinpeng Dong, Xiao Yang et al.ICML 2024 · 15 citations
- DifAttack: Query-Efficient Black-Box Adversarial Attack via Disentangled Feature SpaceJun Liu, Jiantao Zhou, Jiandian Zeng, Jinyu TianAAAI 2024 · 2 citations
- Ensemble-based Blackbox Attacks on Dense PredictionZikui Cai, Yaoteng Tan, M. Salman AsifCVPR 2023
Builds on10
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Black-Box Adversarial Attack with Transferable Model-based EmbeddingZhichao Huang, Tong ZhangICLR 2020 · 131 citations
- Guessing Smart: Biased Sampling for Efficient Black-Box Adversarial AttacksThomas Brunner, Frederik Diehl, Michael Truong-Le, Alois C. KnollICCV 2019 · 127 citations
- Diversity can be Transferred: Output Diversification for White- and Black-box AttacksYusuke Tashiro, Yang Song, Stefano ErmonNeurIPS 2020 · 114 citations
- Learning Black-Box Attackers with Transferable Priors and Query FeedbackJiancheng Yang, Yangzhou Jiang, Xiaoyang Huang, Bingbing Ni et al.NeurIPS 2020 · 96 citations
Related papers
- Boosting Ray Search Procedure of Hard-label Attacks with Transfer-based PriorsChen Ma, Xinjie Xu, Shuyu Cheng, Qi XuanICLR 2025
- MGAAttack: Toward More Query-efficient Black-box Attack by Microbial Genetic AlgorithmLina Wang, Kang Yang, Wenqi Wang, Run Wang et al.ACM MM 2020 · 9 citations
- Training Meta-Surrogate Model for Transferable Adversarial AttackYunxiao Qin, Yuanhao Xiong, Jinfeng Yi, Cho-Jui HsiehAAAI 2023 · 31 citations
- Boosting Black-Box Attack with Partially Transferred Conditional Adversarial DistributionYan Feng, Baoyuan Wu, Yanbo Fan, Li Liu et al.CVPR 2022 · 34 citations
- Perturbing Across the Feature Hierarchy to Improve Standard and Strict Blackbox Attack TransferabilityNathan Inkawhich, Kevin J. Liang, Binghui Wang, Matthew Inkawhich et al.NeurIPS 2020 · 105 citations
