SeRI: Gradient-Free Sensitive Region Identification in Decision-Based Black-Box Attacks
Feiyang Wang, Xingquan Zuo, Hai Huang, Gang Chen, Hangwei Qian
摘要
Deep neural networks (DNNs) are highly vulnerable to adversarial attacks, where small, carefully crafted perturbations are added to input images to cause misclassification. These perturbations are particularly effective when concentrated in sensitive regions of an image that strongly influence the model’s prediction. However, in decision-based black-box settings, where only the top-1 predicted label is observable and query budgets are strictly limited, identifying sensitive regions becomes extremely challenging. This issue is critical because without accurate region information, decision-based attacks cannot refine adversarial examples effectively, limiting both their efficiency and accuracy. We propose Sensitive Region Identification, SeRI, the first decision-based method that assigns a continuous sensitivity score to each image pixel. It enables fine-grained region discovery and substantially improves the efficiency of adversarial attacks, all without access to gradients, confidence scores, or surrogate models. SeRI progressively partitions the image into finer sub-regions and refines a continuous sensitivity score to capture their true importance. At each iteration, it generates two perturbation variants of the selected region by scaling its magnitude up or down, and compares their decision boundaries to derive an accurate, continuous characterization of pixel sensitivity. SeRI further divides selected region into smaller sub-regions, recursively refining the search for sensitive areas. This recursive refinement process enables more precise sensitivity estimation through fine-grained analysis, distinguishing SeRI from prior binary or one-shot region selection approaches. Experiments on two benchmark datasets show that SeRI significantly enhances state-of-the-art decision-based attacks in both targeted and non-targeted attack scenarios. Additionally, SeRI generates precise heatmaps that identify sensitive image regions. The code is available at https://github.com/BUPTAIOC/SeRI.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper21
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn 等ICLR 2021 · 被引用 21,477 次
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- HopSkipJumpAttack: A Query-Efficient Decision-Based AttackJianbo Chen, Michael I. Jordan, Martin J. WainwrightS&P 2020 · 被引用 797 次
- Better Diffusion Models Further Improve Adversarial TrainingZekai Wang, Tianyu Pang, Chao Du, Min Lin 等ICML 2023 · 被引用 300 次
- Sign-OPT: A Query-Efficient Hard-label Adversarial AttackMinhao Cheng, Simranjit Singh, Patrick H. Chen, Pin-Yu Chen 等ICLR 2020 · 被引用 256 次
相关 Paper
- Bias in Zeroth-Order Normal Estimation for Decision-Based AttacksFeiyang Wang, Hangwei Qian, Xingquan Zuo, Gang Chen 等ICML 2026
- AutoDA: Automated Decision-based Iterative Adversarial AttacksQi-An Fu, Yinpeng Dong, Hang Su, Jun Zhu 等USENIX Security 2022
- BRP: Query-Efficient Block Revert Patch for Decision-Based Black-Box Adversarial AttackZenghui Yang, Xingquan Zuo, Gang Chen, Hai Huang 等KDD 2026
- Decision-based Black-box Attack Against Vision Transformers via Patch-wise Adversarial RemovalYucheng Shi, Yahong Han, Yu-an Tan, Xiaohui KuangNeurIPS 2022 · 被引用 43 次
- DeepSearch: a simple and effective blackbox attack for deep neural networksFuyuan Zhang, Sankalan Pal Chowdhury, Maria ChristakisFSE 2020 · 被引用 33 次
