Query Efficient Decision Based Sparse Attacks Against Black-Box Deep Learning Models
Viet Quoc Vo, Ehsan Abbasnejad, Damith Ranasinghe
摘要
Despite our best efforts, deep learning models remain highly vulnerable to even tiny adversarial perturbations applied to the inputs. The ability to extract information from solely the output of a machine learning model to craft adversarial perturbations to black-box models is a practical threat against real-world systems, such as autonomous cars or machine learning models exposed as a service (MLaaS). Of particular interest are sparse attacks. The realization of sparse attacks in black-box models demonstrates that machine learning models are more vulnerable than we believe. Because these attacks aim to minimize the number of perturbed pixels measured by l_0 norm-required to mislead a model by solely observing the decision (the predicted label) returned to a model query; the so-called decision-based attack setting. But, such an attack leads to an NP-hard optimization problem. We develop an evolution-based algorithm-SparseEvo-for the problem and evaluate against both convolutional deep neural networks and vision transformers. Notably, vision transformers are yet to be investigated under a decision-based attack setting. SparseEvo requires significantly fewer model queries than the state-of-the-art sparse attack Pointwise for both untargeted and targeted attacks. The attack algorithm, although conceptually simple, is also competitive with only a limited query budget against the state-of-the-art gradient-based whitebox attacks in standard computer vision tasks such as ImageNet. Importantly, the query efficient SparseEvo, along with decision-based attacks, in general, raise new questions regarding the safety of deployed systems and poses new directions to study and understand the robustness of machine learning models.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- Efficient Decision-based Black-box Patch Attacks on Video RecognitionKaixun Jiang, Zhaoyu Chen, Hao Huang, Jiafeng Wang 等ICCV 2023 · 被引用 30 次
- Brusleattack: a Query-Efficient Score- based Black-Box Sparse Adversarial AttackViet Quoc Vo, Ehsan Abbasnejad, Damith RanasingheICLR 2024 · 被引用 14 次
- Bayesian Learning with Information Gain Provably Bounds Risk for a Robust Adversarial DefenseBao Gia Doan, Ehsan Abbasnejad, Javen Qinfeng Shi, Damith C. RanasingheICML 2022 · 被引用 8 次
- Certifiable Black-Box Attacks with Randomized Adversarial Examples: Breaking Defenses with Provable ConfidenceHanbin Hong, Xinyu Zhang, Binghui Wang, Zhongjie Ba 等CCS 2024 · 被引用 3 次
- IMPACT: Irregular Multi-Patch Adversarial Composition Based on Two‑Phase OptimizationZenghui Yang, Xingquan Zuo, Hai Huang, Gang Chen 等NeurIPS 2025 · 被引用 1 次
它引用的顶会 Paper11
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- Training data-efficient image transformers & distillation through attentionHugo Touvron, Matthieu Cord, Matthijs Douze, Francisco Massa 等ICML 2021 · 被引用 8,974 次
- HopSkipJumpAttack: A Query-Efficient Decision-Based AttackJianbo Chen, Michael I. Jordan, Martin J. WainwrightS&P 2020 · 被引用 797 次
- On the Relationship between Self-Attention and Convolutional LayersJean-Baptiste Cordonnier, Andreas Loukas, Martin JaggiICLR 2020 · 被引用 629 次
- Understanding Robustness of Transformers for Image ClassificationSrinadh Bhojanapalli, Ayan Chakrabarti, Daniel Glasner, Daliang Li 等ICCV 2021 · 被引用 501 次
相关 Paper
- AutoDA: Automated Decision-based Iterative Adversarial AttacksQi-An Fu, Yinpeng Dong, Hang Su, Jun Zhu 等USENIX Security 2022
- Black-Box Sparse Adversarial Attack via Multi-Objective Optimisation CVPR ProceedingsPhoenix Neale Williams, Ke LiCVPR 2023
- Towards Decision-based Sparse Attacks on Video RecognitionKaixun Jiang, Zhaoyu Chen, Xinyu Zhou, Jingyu Zhang 等ACM MM 2023 · 被引用 8 次
- A Geometry-Inspired Decision-Based AttackYujia Liu, Seyed-Mohsen Moosavi-Dezfooli, Pascal FrossardICCV 2019 · 被引用 55 次
- Ask, Attend, Attack: An Effective Decision-Based Black-Box Targeted Attack for Image-to-Text ModelsQingyuan Zeng, Zhenzhong Wang, Yiu-ming Cheung, Min JiangNeurIPS 2024 · 被引用 3 次
