USENIX Security2024Top-tier venue
Transferability of White-box Perturbations: Query-Efficient Adversarial Attacks against Commercial DNN Services
Meng Shen, Changyue Li, Qi Li, Hao Lu, Liehuang Zhu, Ke Xu
Abstract
Deep Neural Networks (DNNs) have been proven to be vulnerable to adversarial attacks. Existing decision-based adversarial attacks require large numbers of queries to find an effective adversarial example, resulting in a heavy query cost and also performance degradation under defenses. In this paper, we propose the Dispersed Sampling Attack (DSA), which is a query-efficient decision-based adversarial attack by exploiting the transferability of white-box perturbations. DSA can generate diverse examples with different locations in the embedding space, which provides more information about the adversarial region of substitute models and allows us to search for transferable perturbations. Specifically, DSA samples in a hypersphere centered on an original image, and progressively constrains the perturbation. Extensive experiments are conducted on public datasets to evaluate the performance of DSA in closed-set and open-set scenarios. DSA outperforms the state-of-the-art attacks in terms of both attack success rate (ASR) and average number of queries (AvgQ). Specifically, DSA achieves an ASR of about 90% with an AvgQ of 200 on 4 well-known commercial DNN services.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 84b1569f-47f1-4c9f-a291-7e81b5689adeCited by top-tier papers5
- Adversarial Attack on Black-Box Multi-Agent by Adaptive PerturbationJianming Chen, Yawen Wang, Junjie Wang, Xiaofei Xie et al.AAAI 2026 · 1 citation
- AT-Field: Rethinking the Games in Adversarial TrainingYixiao Xu, Mohan Li, Zhijie Shen, Yuan Liu et al.AAAI 2026
- Low-Cost Hard-Label Adversarial Attack with Theoretical FoundationsJun Liu, Leo Yu Zhang, Fengpeng Li, Isao Echizen et al.USENIX Security 2026
- Constructive Noise Defeats Adversarial Noise: Adversarial Example Detection for Commercial DNN ServicesMeng Shen, Jiangyuan Bi, Hao Yu, Zhenming Bai et al.NDSS 2026
- DShield: Defending against Backdoor Attacks on Graph Neural Networks via Discrepancy LearningHao Yu, Chuan Ma, Xinhang Wan, Jun Wang et al.NDSS 2025
Builds on25
- A ConvNet for the 2020sZhuang Liu, Hanzi Mao, Chao-Yuan Wu, Christoph Feichtenhofer et al.CVPR 2022 · 6,782 citations
- Swin Transformer V2: Scaling Up Capacity and ResolutionZe Liu, Han Hu, Yutong Lin, Zhuliang Yao et al.CVPR 2022 · 2,138 citations
- MagNet: A Two-Pronged Defense against Adversarial ExamplesDongyu Meng, Hao ChenCCS 2017 · 1,295 citations
- HopSkipJumpAttack: A Query-Efficient Decision-Based AttackJianbo Chen, Michael I. Jordan, Martin J. WainwrightS&P 2020 · 797 citations
- Nesterov Accelerated Gradient and Scale Invariance for Adversarial AttacksJiadong Lin, Chuanbiao Song, Kun He, Liwei Wang et al.ICLR 2020 · 765 citations
Related papers
- Black-Box Adversarial Attack with Transferable Model-based EmbeddingZhichao Huang, Tong ZhangICLR 2020 · 131 citations
- A Geometry-Inspired Decision-Based AttackYujia Liu, Seyed-Mohsen Moosavi-Dezfooli, Pascal FrossardICCV 2019 · 55 citations
- DAIR: A Query-Efficient Decision-based Attack on Image Retrieval SystemsMingyang Chen, Junda Lu, Yi Wang, Jianbin Qin et al.SIGIR 2021 · 20 citations
- MGAAttack: Toward More Query-efficient Black-box Attack by Microbial Genetic AlgorithmLina Wang, Kang Yang, Wenqi Wang, Run Wang et al.ACM MM 2020 · 9 citations
- BounceAttack: A Query-Efficient Decision-based Adversarial Attack by Bouncing into the WildJie Wan, Jianhao Fu, Lijin Wang, Ziqi YangS&P 2024 · 13 citations
