One Pixel Adversarial Attacks via Sketched Programs
Tom Yuviler, Dana Drachsler-Cohen
Abstract
Neural networks are successful in various tasks but are also susceptible to adversarial examples. An adversarial example is generated by adding a small perturbation to a correctly-classified input with the goal of causing a network classifier to misclassify. In one pixel attacks, an attacker aims to fool an image classifier by modifying a single pixel. This setting is challenging for two reasons: the perturbation region is very small and the perturbation is not differentiable. To cope, one pixel attacks iteratively generate candidate adversarial examples and submit them to the network until finding a successful candidate. However, existing works require a very large number of queries, which is infeasible in many practical settings, where the attacker is limited to a few thousand queries to the network. We propose a novel approach for computing one pixel attacks. The key idea is to leverage program synthesis and identify an expressive program sketch that enables to compute adversarial examples using significantly fewer queries. We introduce OPPSLA, a synthesizer that, given a classifier and a training set, instantiates the sketch with customized conditions over the input’s pixels and the classifier’s output. OPPSLA employs a stochastic search, inspired by the Metropolis-Hastings algorithm, that synthesizes typed expressions enabling minimization of the number of queries to the classifier. We further show how to extend OPPSLA to compute few pixel attacks minimizing the number of perturbed pixels. We evaluate OPPSLA on several deep networks for CIFAR-10 and ImageNet. We show that OPPSLA obtains a state-of-the-art success rate, often with an order of magnitude fewer queries than existing attacks. We further show that OPPSLA’s programs are transferable to other classifiers, unlike existing one pixel attacks, which run from scratch on every classifier and input.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers2
- Boosting Few-Pixel Robustness Verification via Covering Verification DesignsYuval Shapira, Naor Wiesel, Shahar Shabelman, Dana Drachsler-CohenCAV 2024 · 2 citations
- Multi-modal Sketch-Based Behavior Tree SynthesisWenmeng Zhang, Zhenbang Chen, Weijiang HongOOPSLA 2025
Builds on5
- Why Do Adversarial Attacks Transfer? Explaining Transferability of Evasion and Poisoning AttacksAmbra Demontis, Marco Melis, Maura Pintor, Matthew Jagielski et al.USENIX Security 2019 · 466 citations
- Sparse and Imperceivable Adversarial AttacksFrancesco Croce, Matthias HeinICCV 2019 · 228 citations
- Towards Transferable Adversarial Attacks on Vision TransformersZhipeng Wei, Jingjing Chen, Micah Goldblum, Zuxuan Wu et al.AAAI 2022 · 156 citations
- Sparse-RS: A Versatile Framework for Query-Efficient Sparse Black-Box Adversarial AttacksFrancesco Croce, Maksym Andriushchenko, Naman D. Singh, Nicolas Flammarion et al.AAAI 2022 · 135 citations
- LooPy: interactive program synthesis with control structuresKasra Ferdowsifard, Shraddha Barke, Hila Peleg, Sorin Lerner et al.OOPSLA 2021 · 18 citations
Related papers
- A Geometry-Inspired Decision-Based AttackYujia Liu, Seyed-Mohsen Moosavi-Dezfooli, Pascal FrossardICCV 2019 · 55 citations
- DeepSearch: a simple and effective blackbox attack for deep neural networksFuyuan Zhang, Sankalan Pal Chowdhury, Maria ChristakisFSE 2020 · 33 citations
- Synthesizing Action Sequences for Modifying Model DecisionsGoutham Ramakrishnan, Yun Chan Lee, Aws AlbarghouthiAAAI 2020 · 37 citations
- Black-Box Sparse Adversarial Attack via Multi-Objective Optimisation CVPR ProceedingsPhoenix Neale Williams, Ke LiCVPR 2023
- SPAA: Stealthy Projector-based Adversarial Attacks on Deep Image ClassifiersBingyao Huang, Haibin LingIEEE VR 2022 · 16 citations
