A Geometry-Inspired Decision-Based Attack
Yujia Liu, Seyed-Mohsen Moosavi-Dezfooli, Pascal Frossard
Abstract
Deep neural networks have recently achieved tremendous success in image classification. Recent studies have however shown that they are easily misled into incorrect classification decisions by adversarial examples. Adversaries can even craft attacks by querying the model in black-box settings, where no information about the model is released except its final decision. Such decision-based attacks usually require lots of queries, while real-world image recognition systems might actually restrict the number of queries. In this paper, we propose qFool, a novel decision-based attack algorithm that can generate adversarial examples using a small number of queries. The qFool method can drastically reduce the number of queries compared to previous decision-based attacks while reaching the same quality of adversarial examples. We also enhance our method by constraining adversarial perturbations in low-frequency subspace, which can make qFool even more computationally efficient. Altogether, we manage to fool commercial image recognition systems with a small number of queries, which demonstrates the actual effectiveness of our new algorithm in practice.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a5e51df2-e984-49d6-9c8f-f7c84649d354Cited by top-tier papers15
- Zero-Shot Knowledge Distillation from a Decision-Based Black-Box ModelZi WangICML 2021 · 56 citations
- Boosting Black-Box Attack with Partially Transferred Conditional Adversarial DistributionYan Feng, Baoyuan Wu, Yanbo Fan, Li Liu et al.CVPR 2022 · 34 citations
- CGBA: Curvature-aware Geometric Black-box AttackMd Farhamdur Reza, Ali Rahmati, Tianfu Wu, Huaiyu DaiICCV 2023 · 33 citations
- Aha! Adaptive History-driven Attack for Decision-based Black-box ModelsJie Li, Rongrong Ji, Peixian Chen, Baochang Zhang et al.ICCV 2021 · 25 citations
- Finding Optimal Tangent Points for Reducing Distortions of Hard-label AttacksChen Ma, Xiangyu Guo, Li Chen, Jun-Hai Yong et al.NeurIPS 2021 · 24 citations
Builds on1
Related papers
- DeepSearch: a simple and effective blackbox attack for deep neural networksFuyuan Zhang, Sankalan Pal Chowdhury, Maria ChristakisFSE 2020 · 33 citations
- AutoDA: Automated Decision-based Iterative Adversarial AttacksQi-An Fu, Yinpeng Dong, Hang Su, Jun Zhu et al.USENIX Security 2022
- DeepRover: A Query-Efficient Blackbox Attack for Deep Neural NetworksFuyuan Zhang, Xinwen Hu, Lei Ma, Jianjun ZhaoFSE 2023 · 7 citations
- GeoDA: A Geometric Framework for Black-Box Adversarial AttacksAli Rahmati, Seyed-Mohsen Moosavi-Dezfooli, Pascal Frossard, Huaiyu DaiCVPR 2020
- BounceAttack: A Query-Efficient Decision-based Adversarial Attack by Bouncing into the WildJie Wan, Jianhao Fu, Lijin Wang, Ziqi YangS&P 2024 · 13 citations
