Bias in Zeroth-Order Normal Estimation for Decision-Based Attacks
Feiyang Wang, Hangwei Qian, Xingquan Zuo, Gang Chen, Ivor Tsang
摘要
Decision-based image attacks commonly rely on zeroth-order (ZO) Monte Carlo probing to estimate decision-boundary normals and iteratively refine adversarial perturbations to minimize the norm. We theoretically analyze and empirically demonstrate an intrinsic inefficiency arising from heterogeneous input sensitivity, where only a small subset of coordinates strongly affects the target model’s predictions. Empirically, with one-bit feedback and a limited query budget, updates on low-sensitivity coordinates are overwhelmed by initialization and sampling noise, preventing their perturbations from exhibiting consistent improvement. By modeling ZO refinement as a stochastic dynamical system, we formally characterize its asymptotic behavior: the optimization enters a stationary regime, where the perturbation aligns (in expectation) with the normal and its coordinate-wise magnitudes encode a local sensitivity ranking. However, this stationarity does not generally yield -optimal perturbations under nonlinear boundaries. Building on this observation, we propose a novel and effective algorithm, Sensitivity-Aware Rescaling (SAR), that leverages this sensitivity signal to infer an importance map from the current best perturbation, then progressively suppresses low-importance regions through a coarse-to-fine schedule to reduce the norm. Extensive experiments show that SAR achieves consistent improvements in perturbation norm, attack success rate, and visual imperceptibility. The code is available at https://github.com/Flyingssheep/SAR.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper20
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn 等ICLR 2021 · 被引用 21,477 次
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- HopSkipJumpAttack: A Query-Efficient Decision-Based AttackJianbo Chen, Michael I. Jordan, Martin J. WainwrightS&P 2020 · 被引用 797 次
- Sign-OPT: A Query-Efficient Hard-label Adversarial AttackMinhao Cheng, Simranjit Singh, Patrick H. Chen, Pin-Yu Chen 等ICLR 2020 · 被引用 256 次
- Guessing Smart: Biased Sampling for Efficient Black-Box Adversarial AttacksThomas Brunner, Frederik Diehl, Michael Truong-Le, Alois C. KnollICCV 2019 · 被引用 127 次
相关 Paper
- SeRI: Gradient-Free Sensitive Region Identification in Decision-Based Black-Box AttacksFeiyang Wang, Xingquan Zuo, Hai Huang, Gang Chen 等ICLR 2026
- Aha! Adaptive History-driven Attack for Decision-based Black-box ModelsJie Li, Rongrong Ji, Peixian Chen, Baochang Zhang 等ICCV 2021 · 被引用 25 次
- Decision-based Black-box Attack Against Vision Transformers via Patch-wise Adversarial RemovalYucheng Shi, Yahong Han, Yu-an Tan, Xiaohui KuangNeurIPS 2022 · 被引用 43 次
- Consistency-Sensitivity Guided Ensemble Black-Box Adversarial Attacks in Low-Dimensional SpacesJianhe Yuan, Zhihai HeICCV 2021 · 被引用 5 次
- A Geometry-Inspired Decision-Based AttackYujia Liu, Seyed-Mohsen Moosavi-Dezfooli, Pascal FrossardICCV 2019 · 被引用 55 次
