SurFree: A Fast Surrogate-Free Black-Box Attack
Thibault Maho, Teddy Furon, Erwan Le Merrer
摘要
Machine learning classifiers are critically prone to evasion attacks. Adversarial examples are slightly modified inputs that are then misclassified, while remaining perceptively close to their originals. Last couple of years have witnessed a striking decrease in the amount of queries a black box attack submits to the target classifier, in order to forge adversarials. This particularly concerns the black box score-based setup, where the attacker has access to top predicted probabilites: the amount of queries went from to millions of to less than a thousand. This paper presents SurFree, a geometrical approach that achieves a drastic reduction in the amount of queries in the hardest setup: black box decision-based attacks (only the top-1 label is available). We first highlight that the most recent attacks in that setup, HSJA [3], QEBA [14] and GeoDA [23] all perform costly gradient surrogate estimations. SurFree proposes to bypass these, by instead focusing on careful trials along diverse directions, guided by precise indications of geometrical properties of the classifier decision boundaries. We motivate this geometric approach before performing a head-to-head comparison with previous attacks with the amount of queries as a first class citizen. We exhibit a faster distortion decay under low query amounts (few hundreds to a thousand), while remaining competitive at higher query budgets. 1
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper25
- Decision-based Black-box Attack Against Vision Transformers via Patch-wise Adversarial RemovalYucheng Shi, Yahong Han, Yu-an Tan, Xiaohui KuangNeurIPS 2022 · 被引用 43 次
- CGBA: Curvature-aware Geometric Black-box AttackMd Farhamdur Reza, Ali Rahmati, Tianfu Wu, Huaiyu DaiICCV 2023 · 被引用 33 次
- A Hard Label Black-box Adversarial Attack Against Graph Neural NetworksJiaming Mu, Binghui Wang, Qi Li, Kun Sun 等CCS 2021 · 被引用 30 次
- Exploring Effective Data for Surrogate Training Towards Black-box AttackXuxiang Sun, Gong Cheng, Hongda Li, Lei Pei 等CVPR 2022 · 被引用 26 次
- Aha! Adaptive History-driven Attack for Decision-based Black-box ModelsJie Li, Rongrong Ji, Peixian Chen, Baochang Zhang 等ICCV 2021 · 被引用 25 次
它引用的顶会 Paper4
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- HopSkipJumpAttack: A Query-Efficient Decision-Based AttackJianbo Chen, Michael I. Jordan, Martin J. WainwrightS&P 2020 · 被引用 797 次
- QEBA: Query-Efficient Boundary-Based Blackbox AttackHuichen Li, Xiaojun Xu, Xiaolu Zhang, Shuang Yang 等CVPR 2020
- GeoDA: A Geometric Framework for Black-Box Adversarial AttacksAli Rahmati, Seyed-Mohsen Moosavi-Dezfooli, Pascal Frossard, Huaiyu DaiCVPR 2020
相关 Paper
- GSBAK: top-K Geometric Score-based Black-box AttackMd Farhamdur Reza, Richeng Jin, Tianfu Wu, Huaiyu DaiICLR 2025
- Finding Optimal Tangent Points for Reducing Distortions of Hard-label AttacksChen Ma, Xiangyu Guo, Li Chen, Jun-Hai Yong 等NeurIPS 2021 · 被引用 24 次
- RamBoAttack: A Robust and Query Efficient Deep Neural Network Decision ExploitViet Quoc Vo, Ehsan Abbasnejad, Damith C. RanasingheNDSS 2022
- Boosting Ray Search Procedure of Hard-label Attacks with Transfer-based PriorsChen Ma, Xinjie Xu, Shuyu Cheng, Qi XuanICLR 2025
- Sign Bits Are All You Need for Black-Box AttacksAbdullah Al-Dujaili, Una-May O'ReillyICLR 2020 · 被引用 93 次
