Attackability Characterization of Adversarial Evasion Attack on Discrete Data
Yutong Wang, Yufei Han, Hongyan Bao, Yun Shen, Fenglong Ma, Jin Li, Xiangliang Zhang
Abstract
Evasion attack on discrete data is a challenging, while practically interesting research topic. It is intrinsically an NP-hard combinatorial optimization problem. Characterizing the conditions guaranteeing the solvability of an evasion attack task thus becomes the key to understand the adversarial threat. Our study is inspired by the weak submodularity theory. We characterize the attackability of a targeted classifier on discrete data in evasion attack by bridging the attackability measurement and the regularity of the targeted classifier. Based on our attackability analysis, we propose a computationally efficient orthogonal matching pursuit-guided attack method for evasion attack on discrete data. It provides provably computational efficiency and attack performances. Substantial experimental results on real-world datasets validate the proposed attackability conditions and the effectiveness of the proposed attack method.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 660227c5-edda-4ab2-9c9e-954d642ba0fbCited by top-tier papers7
- Constrained Adaptive Attack: Effective Adversarial Attack Against Deep Neural Networks for Tabular DataThibault Simonetto, Salah Ghamizi, Maxime CordyNeurIPS 2024 · 18 citations
- Robust Spatiotemporal Traffic Forecasting with Reinforced Dynamic Adversarial TrainingFan Liu, Weijia Zhang, Hao LiuKDD 2023 · 15 citations
- Characterizing the Evasion Attackability of Multi-label ClassifiersZhuo Yang, Yufei Han, Xiangliang ZhangAAAI 2021 · 11 citations
- Probabilistic Categorical Adversarial Attack and Adversarial TrainingHan Xu, Pengfei He, Jie Ren, Yuxuan Wan et al.ICML 2023 · 7 citations
- Towards Efficient and Domain-Agnostic Evasion Attack with High-Dimensional Categorical InputsHongyan Bao, Yufei Han, Yujun Zhou, Xin Gao et al.AAAI 2023 · 5 citations
Related papers
- Towards Understanding the Robustness Against Evasion Attack on Categorical DataHongyan Bao, Yufei Han, Yujun Zhou, Yun Shen et al.ICLR 2022 · 10 citations
- Flexible, Efficient, and Stable Adversarial Attacks on Machine UnlearningZihan Zhou, Yang Zhou, Zijie Zhang, Lingjuan Lyu et al.ICML 2025
- Evading Classifiers by Morphing in the DarkHung Dang, Yue Huang, Ee-Chien ChangCCS 2017 · 125 citations
- Exploring the Orthogonality and Linearity of Backdoor AttacksKaiyuan Zhang, Siyuan Cheng, Guangyu Shen, Guanhong Tao et al.S&P 2024 · 11 citations
- BinarizedAttack: Structural Poisoning Attacks to Graph-based Anomaly DetectionYulin Zhu, Yuni Lai, Kaifa Zhao, Xiapu Luo et al.ICDE 2022 · 26 citations
