Progressive-Scale Boundary Blackbox Attack via Projective Gradient Estimation
Jiawei Zhang, Linyi Li, Huichen Li, Xiaolu Zhang, Shuang Yang, Bo Li
Abstract
Boundary based blackbox attack has been recognized as practical and effective, given that an attacker only needs to access the final model prediction. However, the query efficiency of it is in general high especially for high dimensional image data. In this paper, we show that such efficiency highly depends on the scale at which the attack is applied, and attacking at the optimal scale significantly improves the efficiency. In particular, we propose a theoretical framework to analyze and show three key characteristics to improve the query efficiency. We prove that there exists an optimal scale for projective gradient estimation. Our framework also explains the satisfactory performance achieved by existing boundary blackbox attacks. Based on our theoretical framework, we propose Progressive-Scale enabled projective Boundary Attack (PSBA) to improve the query efficiency via progressive scaling techniques. In particular, we employ Progressive-GAN to optimize the scale of projections, which we call PSBA-PGAN. We evaluate our approach on both spatial and frequency scales. Extensive experiments on MNIST, CIFAR-10, CelebA, and ImageNet against different models including a real-world face recognition API show that PSBA-PGAN significantly outperforms existing baseline attacks in terms of query efficiency and attack success rate. We also observe relatively stable optimal scales for different models and datasets. The code is publicly available at https://github.com/ AI-secure/PSBA .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 9934fc28-ee96-4301-99e3-dd1cb84eb082Cited by top-tier papers8
- G-PATE: Scalable Differentially Private Data Generator via Private Aggregation of Teacher DiscriminatorsYunhui Long, Boxin Wang, Zhuolin Yang, Bhavya Kailkhura et al.NeurIPS 2021 · 91 citations
- Fingerprinting Deep Neural Networks Globally via Universal Adversarial PerturbationsZirui Peng, Shaofeng Li, Guoxing Chen, Cheng Zhang et al.CVPR 2022 · 66 citations
- Improving Certified Robustness via Statistical Learning with Logical ReasoningZhuolin Yang, Zhikuan Zhao, Boxin Wang, Jiawei Zhang et al.NeurIPS 2022 · 16 citations
- Query Efficient Decision Based Sparse Attacks Against Black-Box Deep Learning ModelsViet Quoc Vo, Ehsan Abbasnejad, Damith RanasingheICLR 2022 · 15 citations
- TPC: Transformation-Specific Smoothing for Point Cloud ModelsWenda Chu, Linyi Li, Bo LiICML 2022 · 14 citations
Builds on10
- HopSkipJumpAttack: A Query-Efficient Decision-Based AttackJianbo Chen, Michael I. Jordan, Martin J. WainwrightS&P 2020 · 797 citations
- Sign-OPT: A Query-Efficient Hard-label Adversarial AttackMinhao Cheng, Simranjit Singh, Patrick H. Chen, Pin-Yu Chen et al.ICLR 2020 · 256 citations
- Randomized Smoothing of All Shapes and SizesGreg Yang, Tony Duan, J. Edward Hu, Hadi Salman et al.ICML 2020 · 237 citations
- Diversity can be Transferred: Output Diversification for White- and Black-box AttacksYusuke Tashiro, Yang Song, Stefano ErmonNeurIPS 2020 · 114 citations
- RayS: A Ray Searching Method for Hard-label Adversarial AttackJinghui Chen, Quanquan GuKDD 2020 · 108 citations
Related papers
- QEBA: Query-Efficient Boundary-Based Blackbox AttackHuichen Li, Xiaojun Xu, Xiaolu Zhang, Shuang Yang et al.CVPR 2020
- A Frank-Wolfe Framework for Efficient and Effective Adversarial AttacksJinghui Chen, Dongruo Zhou, Jinfeng Yi, Quanquan GuAAAI 2020 · 78 citations
- Projection & Probability-Driven Black-Box AttackJie Li, Rongrong Ji, Hong Liu, Jianzhuang Liu et al.CVPR 2020
- Boosting Ray Search Procedure of Hard-label Attacks with Transfer-based PriorsChen Ma, Xinjie Xu, Shuyu Cheng, Qi XuanICLR 2025
- ADBA: Approximation Decision Boundary Approach for Black-Box Adversarial AttacksFeiyang Wang, Xingquan Zuo, Hai Huang, Gang ChenAAAI 2025 · 14 citations
