Adversarial Eigen Attack on BlackBox Models
Linjun Zhou, Peng Cui, Xingxuan Zhang, Yinan Jiang, Shiqiang Yang
Abstract
Black-box adversarial attack has aroused much research attention for its difficulty on nearly no available information of the attacked model and the additional constraint on the query budget. A common way to improve attack efficiency is to transfer the gradient information of a white-box substitute model trained on an extra dataset. In this paper, we deal with a more practical setting where a pre-trained white-box model with network parameters is provided without extra training data. To solve the model mismatch problem between the white-box and black-box models, we propose a novel algorithm EigenBA by systematically integrating gradient-based white-box method and zeroth-order optimization in black-box methods. We theoretically show the optimal directions of perturbations for each step are closely related to the right singular vectors of the Jacobian matrix of the pretrained white-box model. Extensive experiments on ImageNet, CIFAR-10 and WebVision show that EigenBA can consistently and significantly outperform state-of-the-art baselines in terms of success rate and attack efficiency.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 8a5548a1-803a-461c-a550-380fc9923a46Cited by top-tier papers2
- Robust Fraud Transaction Detection: A Two-Player Game ApproachQi Tan, Yi Zhao, Laizhong Cui, Qi Li et al.NDSS 2026
- One Leak Away: How Pretrained Model Exposure Amplifies Jailbreak Risks in Finetuned LLMsYixin Tan, Yu Zhe, Rui Wen, Jun SakumaCCS 2026
Builds on5
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Black-Box Adversarial Attack with Transferable Model-based EmbeddingZhichao Huang, Tong ZhangICLR 2020 · 131 citations
- Learning Black-Box Attackers with Transferable Priors and Query FeedbackJiancheng Yang, Yangzhou Jiang, Xiaoyang Huang, Bingbing Ni et al.NeurIPS 2020 · 96 citations
- BayesOpt Adversarial AttackBinxin Ru, Adam D. Cobb, Arno Blaas, Yarin GalICLR 2020 · 85 citations
- Momentum Contrast for Unsupervised Visual Representation LearningKaiming He, Haoqi Fan, Yuxin Wu, Saining Xie et al.CVPR 2020
Related papers
- Efficient Black-box Adversarial Attacks via Bayesian Optimization Guided by a Function PriorShuyu Cheng, Yibo Miao, Yinpeng Dong, Xiao Yang et al.ICML 2024 · 15 citations
- MGAAttack: Toward More Query-efficient Black-box Attack by Microbial Genetic AlgorithmLina Wang, Kang Yang, Wenqi Wang, Run Wang et al.ACM MM 2020 · 9 citations
- Boosting Ray Search Procedure of Hard-label Attacks with Transfer-based PriorsChen Ma, Xinjie Xu, Shuyu Cheng, Qi XuanICLR 2025
- Towards Efficient Data Free Blackbox Adversarial AttackJie Zhang, Bo Li, Jianghe Xu, Shuang Wu et al.CVPR 2022 · 52 citations
- Meta Gradient Adversarial AttackZheng Yuan, Jie Zhang, Yunpei Jia, Chuanqi Tan et al.ICCV 2021 · 95 citations
