USENIX Security2020Top-tier venue
Hybrid Batch Attacks: Finding Black-box Adversarial Examples with Limited Queries
Fnu Suya, Jianfeng Chi, David Evans, Yuan Tian
Abstract
We study adversarial examples in a black-box setting where the adversary only has API access to the target model and each query is expensive. Prior work on black-box adversarial examples follows one of two main strategies: (1) transfer attacks use white-box attacks on local models to find candidate adversarial examples that transfer to the target model, and (2) optimization-based attacks use queries to the target model and apply optimization techniques to search for adversarial examples. We propose hybrid attacks that combine both strategies, using candidate adversarial examples from local models as starting points for optimization-based attacks and using labels learned in optimization-based attacks to tune local models for finding transfer candidates. We empirically demonstrate on the MNIST, CIFAR10, and ImageNet datasets that our hybrid attack strategy reduces cost and improves success rates. We also introduce a seed prioritization strategy which enables attackers to focus their resources on the most promising seeds. Combining hybrid attacks with our seed prioritization strategy enables batch attacks that can reliably find adversarial examples with only a handful of queries.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 97aa22e2-4941-47f7-ac07-4116aa5a4018Cited by top-tier papers33
- Dirty Road Can Attack: Security of Deep Learning based Automated Lane Centering under Physical-World AttackTakami Sato, Junjie Shen, Ningfei Wang, Yunhan Jia et al.USENIX Security 2021 · 152 citations
- Diversity can be Transferred: Output Diversification for White- and Black-box AttacksYusuke Tashiro, Yang Song, Stefano ErmonNeurIPS 2020 · 114 citations
- Composite Adversarial AttacksXiaofeng Mao, Yuefeng Chen, Shuhui Wang, Hang Su et al.AAAI 2021 · 60 citations
- Voiceprint Mimicry Attack Towards Speaker Verification System in Smart HomeLei Zhang, Yan Meng, Jiahao Yu, Chong Xiang et al.INFOCOM 2020 · 49 citations
- Local Bayesian optimization via maximizing probability of descentQuan Nguyen, Kaiwen Wu, Jacob R. Gardner, Roman GarnettNeurIPS 2022 · 41 citations
Builds on2
Related papers
- Black-Box Adversarial Attack with Transferable Model-based EmbeddingZhichao Huang, Tong ZhangICLR 2020 · 131 citations
- Boosting Ray Search Procedure of Hard-label Attacks with Transfer-based PriorsChen Ma, Xinjie Xu, Shuyu Cheng, Qi XuanICLR 2025
- Blackbox Attacks via Surrogate Ensemble SearchZikui Cai, Chengyu Song, Srikanth V. Krishnamurthy, Amit Roy-Chowdhury et al.NeurIPS 2022 · 32 citations
- Efficient Black-box Adversarial Attacks via Bayesian Optimization Guided by a Function PriorShuyu Cheng, Yibo Miao, Yinpeng Dong, Xiao Yang et al.ICML 2024 · 15 citations
- Boosting Black-Box Attack with Partially Transferred Conditional Adversarial DistributionYan Feng, Baoyuan Wu, Yanbo Fan, Li Liu et al.CVPR 2022 · 34 citations
