Attackability Characterization of Adversarial Evasion Attack on Discrete Data
Yutong Wang, Yufei Han, Hongyan Bao, Yun Shen, Fenglong Ma, Jin Li, Xiangliang Zhang
摘要
Evasion attack on discrete data is a challenging, while practically interesting research topic. It is intrinsically an NP-hard combinatorial optimization problem. Characterizing the conditions guaranteeing the solvability of an evasion attack task thus becomes the key to understand the adversarial threat. Our study is inspired by the weak submodularity theory. We characterize the attackability of a targeted classifier on discrete data in evasion attack by bridging the attackability measurement and the regularity of the targeted classifier. Based on our attackability analysis, we propose a computationally efficient orthogonal matching pursuit-guided attack method for evasion attack on discrete data. It provides provably computational efficiency and attack performances. Substantial experimental results on real-world datasets validate the proposed attackability conditions and the effectiveness of the proposed attack method.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper7
- Constrained Adaptive Attack: Effective Adversarial Attack Against Deep Neural Networks for Tabular DataThibault Simonetto, Salah Ghamizi, Maxime CordyNeurIPS 2024 · 被引用 18 次
- Robust Spatiotemporal Traffic Forecasting with Reinforced Dynamic Adversarial TrainingFan Liu, Weijia Zhang, Hao LiuKDD 2023 · 被引用 15 次
- Characterizing the Evasion Attackability of Multi-label ClassifiersZhuo Yang, Yufei Han, Xiangliang ZhangAAAI 2021 · 被引用 11 次
- Probabilistic Categorical Adversarial Attack and Adversarial TrainingHan Xu, Pengfei He, Jie Ren, Yuxuan Wan 等ICML 2023 · 被引用 7 次
- Towards Efficient and Domain-Agnostic Evasion Attack with High-Dimensional Categorical InputsHongyan Bao, Yufei Han, Yujun Zhou, Xin Gao 等AAAI 2023 · 被引用 5 次
相关 Paper
- Towards Understanding the Robustness Against Evasion Attack on Categorical DataHongyan Bao, Yufei Han, Yujun Zhou, Yun Shen 等ICLR 2022 · 被引用 10 次
- Flexible, Efficient, and Stable Adversarial Attacks on Machine UnlearningZihan Zhou, Yang Zhou, Zijie Zhang, Lingjuan Lyu 等ICML 2025
- Evading Classifiers by Morphing in the DarkHung Dang, Yue Huang, Ee-Chien ChangCCS 2017 · 被引用 125 次
- Exploring the Orthogonality and Linearity of Backdoor AttacksKaiyuan Zhang, Siyuan Cheng, Guangyu Shen, Guanhong Tao 等S&P 2024 · 被引用 11 次
- BinarizedAttack: Structural Poisoning Attacks to Graph-based Anomaly DetectionYulin Zhu, Yuni Lai, Kaifa Zhao, Xiapu Luo 等ICDE 2022 · 被引用 26 次
