A Stable and Efficient Data-Free Model Attack With Label-Noise Data Generation

被引:0
|
作者
Zhang, Zhixuan [1 ]
Zheng, Xingjian [2 ]
Qing, Linbo [1 ]
Liu, Qi [3 ]
Wang, Pingyu [4 ]
Liu, Yu [4 ]
Liao, Jiyang [4 ]
机构
[1] Sichuan Univ, Sch Cyber Sci & Engn, Chengdu 610207, Peoples R China
[2] Frost Drill Intellectual Software Pte Ltd, Int Plaza, Singapore 079903, Singapore
[3] South China Univ Technol, Sch Future Technol, Guangzhou 511442, Peoples R China
[4] Sichuan Univ, Coll Elect & Informat Engn, Chengdu 610065, Peoples R China
基金
中国国家自然科学基金;
关键词
Training; Closed box; Generators; Data models; Data collection; Adaptation models; Diversity methods; Cloning; Glass box; Computational modeling; Deep neural network; data-free; adversarial examples; closed-box attack;
D O I
10.1109/TIFS.2025.3550066
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The objective of a data-free closed-box adversarial attack is to attack a victim model without using internal information, training datasets or semantically similar substitute datasets. Concerned about stricter attack scenarios, recent studies have tried employing generative networks to synthesize data for training substitute models. Nevertheless, these approaches concurrently encounter challenges associated with unstable training and diminished attack efficiency. In this paper, we propose a novel query-efficient data-free closed-box adversarial attack method. To mitigate unstable training, for the first time, we directly manipulate the intermediate-layer feature of a generator without relying on any substitute models. Specifically, a label noise-based generation module is created to enhance the intra-class patterns by incorporating partial historical information during the learning process. Additionally, we present a feature-disturbed diversity generation method to augment the inter-class distance. Meanwhile, we propose an adaptive intra-class attack strategy to heighten attack capability within a limited query budget. In this strategy, entropy-based distance is utilized to characterize the relative information from model outputs, while positive classes and negative samples are used to enhance low attack efficiency. The comprehensive experiments conducted on six datasets demonstrate the superior performance of our method compared to six state-of-the-art data-free closed-box competitors in both label-only and probability-only attack scenarios. Intriguingly, our method can realize the highest attack success rate on the online Microsoft Azure model under an extremely low query budget. Additionally, the proposed approach not only achieves more stable training but also significantly reduces the query count for a more balanced data generation. Furthermore, our method can maintain the best performance under the existing defense models and a limited query budget.
引用
收藏
页码:3131 / 3145
页数:15
相关论文
共 50 条
  • [21] On the Universal Adversarial Perturbations for Efficient Data-free Adversarial Detection
    Gao, Songyang
    Dou, Shihan
    Zhang, Qi
    Huang, Xuanjing
    Ma, Jin
    Shan, Ying
    FINDINGS OF THE ASSOCIATION FOR COMPUTATIONAL LINGUISTICS (ACL 2023), 2023, : 13573 - 13581
  • [22] The Complexity of Data-Free Nfer
    Kauffman, Sean
    Larsen, Kim Guldstrand
    Zimmermann, Martin
    RUNTIME VERIFICATION, RV 2024, 2025, 15191 : 174 - 191
  • [23] Training A Secure Model Against Data-Free Model Extraction
    Wang, Zhenyi
    Li Shen
    Guo, Junfeng
    Duan, Tiehang
    Luan, Siyu
    Liu, Tongliang
    Gao, Mingchen
    COMPUTER VISION - ECCV 2024, PT LXXIX, 2025, 15137 : 323 - 340
  • [24] Synthetic data generation method for data-free knowledge distillation in regression neural networks
    Zhou, Tianxun
    Chiam, Keng-Hwee
    EXPERT SYSTEMS WITH APPLICATIONS, 2023, 227
  • [25] Contrastive Model Inversion for Data-Free Knowledge Distillation
    Fang, Gongfan
    Song, Jie
    Wang, Xinchao
    Shen, Chengchao
    Wang, Xingen
    Song, Mingli
    PROCEEDINGS OF THE THIRTIETH INTERNATIONAL JOINT CONFERENCE ON ARTIFICIAL INTELLIGENCE, IJCAI 2021, 2021, : 2374 - 2380
  • [26] Adaptive Data-Free Quantization
    Qian, Biao
    Wang, Yang
    Hong, Richang
    Wang, Meng
    2023 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION, CVPR, 2023, : 7960 - 7968
  • [27] DST: Dynamic Substitute Training for Data-free Black-box Attack
    Wang, Wenxuan
    Qian, Xuelin
    Fu, Yanwei
    Xue, Xiangyang
    2022 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2022, : 14341 - 14350
  • [28] SCME: A Self-contrastive Method for Data-Free and Query-Limited Model Extraction Attack
    Liu, Renyang
    Zhang, Jinhong
    Lam, Kwok-Yan
    Zhao, Jun
    Zhou, Wei
    NEURAL INFORMATION PROCESSING, ICONIP 2023, PT V, 2024, 14451 : 370 - 382
  • [29] Data-free stealing attack and defense strategy for industrial fault diagnosis system
    Jia, Tianyuan
    Tian, Ying
    Yin, Zhong
    Zhang, Wei
    Sun, Zhanquan
    CHEMICAL ENGINEERING RESEARCH & DESIGN, 2025, 216 : 200 - 215
  • [30] Customizing Synthetic Data for Data-Free Student Learning
    Luo, Shiya
    Chen, Defang
    Wang, Can
    2023 IEEE INTERNATIONAL CONFERENCE ON MULTIMEDIA AND EXPO, ICME, 2023, : 1817 - 1822