DAIR: A Query-Efficient Decision-based Attack on Image Retrieval Systems
Mingyang Chen, Junda Lu, Yi Wang, Jianbin Qin, Wei Wang
摘要
There is an increasing interest in studying adversarial attacks on image retrieval systems. However, most of the existing attack methods are based on the white-box setting, where the attackers have access to all the model and database details, which is a strong assumption for practical attacks. The generic transfer-based attack also requires substantial resources yet the effect was shown to be unreliable. In this paper, we make the first attempt in proposing a query-efficient decision-based attack framework for the image retrieval (DAIR) to completely subvert the top-K retrieval results with human imperceptible perturbations. We propose an optimization-based method with a smoothed utility function to overcome the challenging discrete nature of the problem. To further improve the query efficiency, we propose a novel sampling method that can achieve the transferability between the surrogate and the target model efficiently. Our comprehensive experimental evaluation on the benchmark datasets shows that our DAIR method outperforms significantly the state-of-the-art decision-based methods. We also demonstrate that real image retrieval engines (Bing Visual Search and Face++ engines) can be attacked successfully with only several hundreds of queries.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper6
- Topic-oriented Adversarial Attacks against Black-box Neural Ranking ModelsYu-An Liu, Ruqing Zhang, Jiafeng Guo, Maarten de Rijke 等SIGIR 2023 · 被引用 20 次
- Once and for All: Universal Transferable Adversarial Perturbation against Deep Hashing-Based Facial Image RetrievalLong Tang, Dengpan Ye, Yunna Lv, Chuanxi Chen 等AAAI 2024 · 被引用 13 次
- HUANG: A Robust Diffusion Model-based Targeted Adversarial Attack Against Deep Hashing RetrievalChihan Huang, Xiaobo ShenAAAI 2025 · 被引用 5 次
- Collapse-Aware Triplet Decoupling for Adversarially Robust Image RetrievalQiwei Tian, Chenhao Lin, Zhengyu Zhao, Qian Li 等ICML 2024 · 被引用 3 次
- Toward Understanding Adversarial Distillation: Why Robust Teachers FailHongsin Lee, Hye Won ChungICML 2026
相关 Paper
- QAIR: Practical Query-Efficient Black-Box Attacks for Image RetrievalXiaodan Li, Jinfeng Li, Yuefeng Chen, Shaokai Ye 等CVPR 2021
- Transferability of White-box Perturbations: Query-Efficient Adversarial Attacks against Commercial DNN ServicesMeng Shen, Changyue Li, Qi Li, Hao Lu 等USENIX Security 2024 · 被引用 8 次
- Unsupervised Corpus Poisoning Attacks in Continuous Space for Dense RetrievalYongkang Li, Panagiotis Eustratiadis, Simon Lupart, Evangelos KanoulasSIGIR 2025 · 被引用 3 次
- Universal Perturbation Attack Against Image RetrievalJie Li, Rongrong Ji, Hong Liu, Xiaopeng Hong 等ICCV 2019 · 被引用 115 次
- Black-Box Adversarial Attack with Transferable Model-based EmbeddingZhichao Huang, Tong ZhangICLR 2020 · 被引用 131 次
