Query-efficient black-box ensemble attack via dynamic surrogate weighting

被引:0
|
作者
Hu, Cong [1 ]
He, Zhichao
Wu, Xiaojun
机构
[1] Jiangnan Univ, Sch Artificial Intelligence & Comp Sci, Wuxi 214122, Jiangsu, Peoples R China
基金
中国博士后科学基金; 中国国家自然科学基金;
关键词
Black-box attack; Ensemble strategies; Deep neural networks; Transferable adversarial example; Image classification;
D O I
10.1016/j.patcog.2024.111263
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
In recent years, deep neural networks (DNNs) have been widely applied across various fields, but the sensitivity of DNNs to adversarial attacks has attracted widespread attention. Existing research has highlighted the potential of ensemble attacks, which blend the strengths of transfer-based and query-based methods, to create highly transferable adversarial examples. It has been noted that simply amalgamating outputs from various models, without considering the gradient variances, can lead to low transferability. Furthermore, employing static model weights or inefficient weight update strategies may contribute to an unnecessary proliferation of query iterations. To address these issues, this paper introduces a novel black-box ensemble attack algorithm (DSWEA) that combines the Ranking Variance Reduced (RVR) ensemble strategy with the Dynamic Surrogate Weighting (DSW) weight update strategy. RVR employs multiple internal iterations within each query to compute and accumulate unbiased gradients, which are then used to update adversarial examples. This optimization of the gradient diminishes the negative impact of excessive gradient discrepancies between models, thereby enhancing the transferability of perturbations. DSW dynamically adjusts the surrogate weights in each query iteration based on model gradient information, guiding the efficient generation of perturbations. We conduct extensive experiments on the ImageNet and CIFAR-10 datasets, involving various models with varying architectures. Our empirical results reveal that our methodology outperforms existing state-of-the-art techniques, showcasing superior efficacy in terms of Attack Success Rate (ASR) and Average Number of Queries (ANQ).
引用
收藏
页数:12
相关论文
共 50 条
  • [41] Query-efficient decision-based attack via sampling distribution reshaping
    Sun, Xuxiang
    Cheng, Gong
    Pei, Lei
    Han, Junwei
    PATTERN RECOGNITION, 2022, 129
  • [42] HopSkipJumpAttack: A Query-Efficient Decision-Based Attack
    Chen, Jianbo
    Jordan, Michael, I
    Wainwright, Martin J.
    2020 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP 2020), 2020, : 1277 - 1294
  • [43] Towards Efficient Data Free Black-box Adversarial Attack
    Zhang, Jie
    Li, Bo
    Xu, Jianghe
    Wu, Shuang
    Ding, Shouhong
    Zhang, Lei
    Wu, Chao
    2022 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR 2022), 2022, : 15094 - 15104
  • [44] Triangle Attack: A Query-Efficient Decision-Based Adversarial Attack
    Wang, Xiaosen
    Zhang, Zeliang
    Tong, Kangheng
    Gong, Dihong
    He, Kun
    Li, Zhifeng
    Liu, Andwei
    COMPUTER VISION - ECCV 2022, PT V, 2022, 13665 : 156 - 174
  • [45] TranFuzz: An Ensemble Black-Box Attack Framework Based on Domain Adaptation and Fuzzing
    Li, Hao
    Guo, Shanqing
    Tang, Peng
    Hu, Chengyu
    Chen, Zhenxiang
    INFORMATION AND COMMUNICATIONS SECURITY (ICICS 2021), PT I, 2021, 12918 : 260 - 275
  • [46] Improving query efficiency of black-box attacks via the preference of models
    Yang, Xiangyuan
    Lin, Jie
    Zhang, Hanlin
    Zhao, Peng
    INFORMATION SCIENCES, 2024, 678
  • [47] Parallel Rectangle Flip Attack: A Query-based Black-box Attack against Object Detection
    Liang, Siyuan
    Wu, Baoyuan
    Fan, Yanbo
    Wei, Xingxing
    Cao, Xiaochun
    2021 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2021), 2021, : 7677 - 7687
  • [48] DeepRover: A Query-Efficient Blackbox Attack for Deep Neural Networks
    Zhang, Fuyuan
    Hu, Xinwen
    Ma, Lei
    Zhao, Jianjun
    PROCEEDINGS OF THE 31ST ACM JOINT MEETING EUROPEAN SOFTWARE ENGINEERING CONFERENCE AND SYMPOSIUM ON THE FOUNDATIONS OF SOFTWARE ENGINEERING, ESEC/FSE 2023, 2023, : 1384 - 1394
  • [49] QEBA: Query-Efficient Boundary-Based Blackbox Attack
    Li, Huichen
    Xu, Xiaojun
    Zhang, Xiaolu
    Yang, Shuang
    Li, Bo
    2020 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2020, : 1218 - 1227
  • [50] Query-based black-box attack against medical image segmentation model
    Li, Siyuan
    Huang, Guangji
    Xu, Xing
    Lu, Huimin
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2022, 133 : 331 - 337