Query-efficient black-box ensemble attack via dynamic surrogate weighting

被引:0
|
作者
Hu, Cong [1 ]
He, Zhichao
Wu, Xiaojun
机构
[1] Jiangnan Univ, Sch Artificial Intelligence & Comp Sci, Wuxi 214122, Jiangsu, Peoples R China
基金
中国博士后科学基金; 中国国家自然科学基金;
关键词
Black-box attack; Ensemble strategies; Deep neural networks; Transferable adversarial example; Image classification;
D O I
10.1016/j.patcog.2024.111263
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
In recent years, deep neural networks (DNNs) have been widely applied across various fields, but the sensitivity of DNNs to adversarial attacks has attracted widespread attention. Existing research has highlighted the potential of ensemble attacks, which blend the strengths of transfer-based and query-based methods, to create highly transferable adversarial examples. It has been noted that simply amalgamating outputs from various models, without considering the gradient variances, can lead to low transferability. Furthermore, employing static model weights or inefficient weight update strategies may contribute to an unnecessary proliferation of query iterations. To address these issues, this paper introduces a novel black-box ensemble attack algorithm (DSWEA) that combines the Ranking Variance Reduced (RVR) ensemble strategy with the Dynamic Surrogate Weighting (DSW) weight update strategy. RVR employs multiple internal iterations within each query to compute and accumulate unbiased gradients, which are then used to update adversarial examples. This optimization of the gradient diminishes the negative impact of excessive gradient discrepancies between models, thereby enhancing the transferability of perturbations. DSW dynamically adjusts the surrogate weights in each query iteration based on model gradient information, guiding the efficient generation of perturbations. We conduct extensive experiments on the ImageNet and CIFAR-10 datasets, involving various models with varying architectures. Our empirical results reveal that our methodology outperforms existing state-of-the-art techniques, showcasing superior efficacy in terms of Attack Success Rate (ASR) and Average Number of Queries (ANQ).
引用
收藏
页数:12
相关论文
共 50 条
  • [31] Improved black-box attack based on query and perturbation distribution
    Zhao, Weiwei
    Zeng, Zhigang
    2021 13TH INTERNATIONAL CONFERENCE ON ADVANCED COMPUTATIONAL INTELLIGENCE (ICACI), 2021, : 117 - 125
  • [32] A discrete cosine transform-based query efficient attack on black-box object detectors
    Kuang, Xiaohui
    Gao, Xianfeng
    Wang, Lianfang
    Zhao, Gang
    Ke, Lishan
    Zhang, Quanxin
    INFORMATION SCIENCES, 2021, 546 : 596 - 607
  • [33] A low-query black-box adversarial attack based on transferability
    Ding, Kangyi
    Liu, Xiaolei
    Niu, Weina
    Hu, Teng
    Wang, Yanping
    Zhang, Xiaosong
    KNOWLEDGE-BASED SYSTEMS, 2021, 226
  • [34] QROA: A Black-Box Query-Response Optimization Attack on LLMs
    Capgemini Invent, Paris, France
    不详
    arXiv,
  • [35] Exploring Effective Data for Surrogate Training Towards Black-box Attack
    Sun, Xuxiang
    Cheng, Gong
    Li, Hongda
    Pei, Lei
    Han, Junwei
    2022 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR 2022), 2022, : 15334 - 15343
  • [36] Black-Box Adversarial Attack via Overlapped Shapes
    Williams, Phoenix
    Li, Ke
    Min, Geyong
    PROCEEDINGS OF THE 2022 GENETIC AND EVOLUTIONARY COMPUTATION CONFERENCE COMPANION, GECCO 2022, 2022, : 467 - 468
  • [37] An Evolutionary, Gradient-Free, Query-Efficient, Black-Box Algorithm for Generating Adversarial Instances in Deep Convolutional Neural Networks
    Lapid, Raz
    Haramaty, Zvika
    Sipper, Moshe
    ALGORITHMS, 2022, 15 (11)
  • [38] Query-efficient Partitions for Dynamic Data
    Vasilakis, Nikos
    Palkhiwala, Yash
    Smith, Jonathan M.
    PROCEEDINGS OF THE 8TH ASIA-PACIFIC WORKSHOP ON SYSTEMS (APSYS '17), 2017,
  • [39] Efficient Query-based Black-box Attack against Cross-modal Hashing Retrieval
    Zhu, Lei
    Wang, Tianshi
    Li, Jingjing
    Zhang, Zheng
    Shen, Jialie
    Wang, Xinhua
    ACM TRANSACTIONS ON INFORMATION SYSTEMS, 2023, 41 (03)
  • [40] Black-box re-weighting
    Ytreberg, F. Marty
    Zuckerman, Daniel M.
    BIOPHYSICAL JOURNAL, 2007, : 193A - 193A