Black-Box Sparse Adversarial Attack via Multi-Objective Optimisation CVPR Proceedings
Phoenix Neale Williams, Ke Li
摘要
Deep neural networks (DNNs) are susceptible to adversarial images, raising concerns about their reliability in safety-critical tasks. Sparse adversarial attacks, which limit the number of modified pixels, have shown to be highly effective in causing DNNs to misclassify. However, existing methods often struggle to simultaneously minimize the number of modified pixels and the size of the modifications, often requiring a large number of queries and assuming unrestricted access to the targeted DNN. In contrast, other methods that limit the number of modified pixels often permit unbounded modifications, making them easily detectable.To address these limitations, we propose a novel multi-objective sparse attack algorithm that efficiently minimizes the number of modified pixels and their size during the attack process. Our algorithm draws inspiration from evolutionary computation and incorporates a mechanism for prioritizing objectives that aligns with an attacker's goals. Our approach outperforms existing sparse attacks on CIFAR-10 and ImageNet trained DNN classifiers while requiring only a small query budget, attaining competitive attack success rates while perturbing fewer pixels. Overall, our proposed attack algorithm provides a solution to the limitations of current sparse attack methods by jointly minimizing the number of modified pixels and their size. Our results demonstrate the effectiveness of our approach in restricted scenarios, highlighting its potential to enhance DNN security.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- CamoPatch: An Evolutionary Strategy for Generating Camoflauged Adversarial PatchesPhoenix Neale Williams, Ke LiNeurIPS 2023 · 被引用 22 次
- Human-in-the-Loop Policy Optimization for Preference-Based Multi-Objective Reinforcement LearningTianmeng Hu, Biao Luo, Ke LiICML 2026 · 被引用 3 次
- On the Adversarial Robustness of Multi-Kernel ClusteringHao Yu, Weixuan Liang, Ke Liang, Suyuan Liu 等ICML 2025
- MOS-Attack: A Scalable Multi-objective Adversarial Attack FrameworkPing Guo, Cheng Gong, Xi Lin, Fei Liu 等CVPR 2025
它引用的顶会 Paper9
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- Do Adversarially Robust ImageNet Models Transfer Better?Hadi Salman, Andrew Ilyas, Logan Engstrom, Ashish Kapoor 等NeurIPS 2020 · 被引用 506 次
- Improving Robustness using Generated DataSven Gowal, Sylvestre-Alvise Rebuffi, Olivia Wiles, Florian Stimberg 等NeurIPS 2021 · 被引用 384 次
- Sparse and Imperceivable Adversarial AttacksFrancesco Croce, Matthias HeinICCV 2019 · 被引用 228 次
- Sparse-RS: A Versatile Framework for Query-Efficient Sparse Black-Box Adversarial AttacksFrancesco Croce, Maksym Andriushchenko, Naman D. Singh, Nicolas Flammarion 等AAAI 2022 · 被引用 135 次
相关 Paper
- Sparse and Imperceptible Adversarial Attack via a Homotopy AlgorithmMingkang Zhu, Tianlong Chen, Zhangyang WangICML 2021 · 被引用 33 次
- GSE: Group-wise Sparse and Explainable Adversarial AttacksShpresim Sadiku, Moritz Wagner, Sebastian PokuttaICLR 2025
- Query Efficient Decision Based Sparse Attacks Against Black-Box Deep Learning ModelsViet Quoc Vo, Ehsan Abbasnejad, Damith RanasingheICLR 2022 · 被引用 15 次
- Transferable Structural Sparse Adversarial Attack Via Exact Group Sparsity TrainingDi Ming, Peng Ren, Yunlong Wang, Xin FengCVPR 2024 · 被引用 7 次
- GreedyFool: Distortion-Aware Sparse Adversarial AttackXiaoyi Dong, Dongdong Chen, Jianmin Bao, Chuan Qin 等NeurIPS 2020 · 被引用 87 次
