Delving into Data: Effectively Substitute Training for Black-box Attack
Wenxuan Wang, Bangjie Yin, Taiping Yao, Li Zhang, Yanwei Fu, Shouhong Ding, Jilin Li, Feiyue Huang, Xiangyang Xue
摘要
Deep models have shown their vulnerability when processing adversarial samples. As for the black-box attack, without access to the architecture and weights of the attacked model, training a substitute model for adversarial attacks has attracted wide attention. Previous substitute training approaches focus on stealing the knowledge of the target model based on real training data or synthetic data, without exploring what kind of data can further improve the transferability between the substitute and target models. In this paper, we propose a novel perspective substitute training that focuses on designing the distribution of data used in the knowledge stealing process. More specifically, a diverse data generation module is proposed to synthesize large-scale data with wide distribution. And adversarial substitute training strategy is introduced to focus on the data distributed near the decision boundary. The combination of these two modules can further boost the consistency of the substitute model and target model, which greatly improves the effectiveness of adversarial attack. Extensive experiments demonstrate the efficacy of our method against state-of-the-art competitors under non-target and target attack settings. Detailed visualization and analysis are also provided to help understand the advantage of our method.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper16
- Adv-Attribute: Inconspicuous and Transferable Adversarial Attack on Face RecognitionShuai Jia, Bangjie Yin, Taiping Yao, Shouhong Ding 等NeurIPS 2022 · 被引用 84 次
- Exploring Frequency Adversarial Attacks for Face Forgery DetectionShuai Jia, Chao Ma, Taiping Yao, Bangjie Yin 等CVPR 2022 · 被引用 78 次
- Towards Data-Free Model Stealing in a Hard Label SettingSunandini Sanyal, Sravanti Addepalli, R. Venkatesh BabuCVPR 2022 · 被引用 76 次
- SOTER: Guarding Black-box Inference for General Neural Networks at the EdgeTianxiang Shen, Ji Qi, Jianyu Jiang, Xian Wang 等USENIX ATC 2022 · 被引用 67 次
- Towards Efficient Data Free Blackbox Adversarial AttackJie Zhang, Bo Li, Jianghe Xu, Shuang Wu 等CVPR 2022 · 被引用 52 次
它引用的顶会 Paper5
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- Stealing Machine Learning Models via Prediction APIsFlorian Tramèr, Fan Zhang, Ari Juels, Michael K. Reiter 等USENIX Security 2016 · 被引用 2,088 次
- Hermes Attack: Steal DNN Models with Lossless Inference AccuracyYuankun Zhu, Yueqiang Cheng, Husheng Zhou, Yantao LuUSENIX Security 2021 · 被引用 119 次
- DaST: Data-Free Substitute Training for Adversarial AttacksMingyi Zhou, Jing Wu, Yipeng Liu, Shuaicheng Liu 等CVPR 2020
- Dreaming to Distill: Data-Free Knowledge Transfer via DeepInversionHongxu Yin, Pavlo Molchanov, José M. Álvarez, Zhizhong Li 等CVPR 2020
相关 Paper
- DST: Dynamic Substitute Training for Data-free Black-box AttackWenxuan Wang, Xuelin Qian, Yanwei Fu, Xiangyang XueCVPR 2022 · 被引用 18 次
- KOEnsAttack: Towards Efficient Data-Free Black-Box Adversarial Attacks via Knowledge-Orthogonalized Substitute EnsemblesChaoyong Yang, Jia-Li Yin, Bin Chen, Zhaozhe Hu 等ICCV 2025
- Power of Diversity: Enhancing Data-Free Black-Box Attack with Domain-Augmented LearningYang Wei, Jingyu Tan, Guowen Xu, Zhuoran Ma 等AAAI 2025
- Simulating Unknown Target Models for Query-Efficient Black-Box AttacksChen Ma, Li Chen, Jun-Hai YongCVPR 2021
- Minimizing Maximum Model Discrepancy for Transferable Black-box Targeted AttacksAnqi Zhao, Tong Chu, Yahao Liu, Wen Li 等CVPR 2023
