Black-Box Sparse Adversarial Attack via Multi-Objective Optimisation CVPR Proceedings

被引:11
|
作者
Williams, Phoenix Neale [1 ]
Li, Ke [1 ]
机构
[1] Univ Exeter, Dept Comp Sci, Stocker Rd, Exeter EX4 4PY, Devon, England
基金
英国工程与自然科学研究理事会;
关键词
D O I
10.1109/CVPR52729.2023.01183
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Deep neural networks (DNNs) are susceptible to adversarial images, raising concerns about their reliability in safety-critical tasks. Sparse adversarial attacks, which limit the number of modified pixels, have shown to be highly effective in causing DNNs to misclassify. However, existing methods often struggle to simultaneously minimize the number of modified pixels and the size of the modifications, often requiring a large number of queries and assuming unrestricted access to the targeted DNN. In contrast, other methods that limit the number of modified pixels often permit unbounded modifications, making them easily detectable.To address these limitations, we propose a novel multi-objective sparse attack algorithm that efficiently minimizes the number of modified pixels and their size during the attack process. Our algorithm draws inspiration from evolutionary computation and incorporates a mechanism for prioritizing objectives that aligns with an attacker's goals. Our approach outperforms existing sparse attacks on CIFAR-10 and ImageNet trained DNN classifiers while requiring only a small query budget, attaining competitive attack success rates while perturbing fewer pixels. Overall, our proposed attack algorithm provides a solution to the limitations of current sparse attack methods by jointly minimizing the number of modified pixels and their size. Our results demonstrate the effectiveness of our approach in restricted scenarios, highlighting its potential to enhance DNN security.
引用
收藏
页码:12291 / 12301
页数:11
相关论文
共 50 条
  • [1] An Adversarial Attack Based on Multi-objective Optimization in the Black-Box Scenario: MOEA-APGA II
    Zhang, Chunkai
    Deng, Yepeng
    Guo, Xin
    Wang, Xuan
    Liu, Chuanyi
    INFORMATION AND COMMUNICATIONS SECURITY (ICICS 2019), 2020, 11999 : 603 - 612
  • [2] Black-Box Adversarial Attack via Overlapped Shapes
    Williams, Phoenix
    Li, Ke
    Min, Geyong
    PROCEEDINGS OF THE 2022 GENETIC AND EVOLUTIONARY COMPUTATION CONFERENCE COMPANION, GECCO 2022, 2022, : 467 - 468
  • [3] An efficient general black-box adversarial attack approach based on multi-objective optimization for high dimensional images
    Zhang, Chunkai
    Guo, Xin
    Deng, Yepeng
    Wang, Xuan
    Han, Peiyi
    Liu, Chuanyi
    Zhang, Hanyu
    COMPUTERS & ELECTRICAL ENGINEERING, 2021, 95
  • [4] An efficient general black-box adversarial attack approach based on multi-objective optimization for high dimensional images
    Zhang, Chunkai
    Guo, Xin
    Deng, Yepeng
    Wang, Xuan
    Han, Peiyi
    Liu, Chuanyi
    Zhang, Hanyu
    Computers and Electrical Engineering, 2021, 95
  • [5] A statistical model-based algorithm for 'black-box' multi-objective optimisation
    Zilinskas, Antanas
    INTERNATIONAL JOURNAL OF SYSTEMS SCIENCE, 2014, 45 (01) : 82 - 93
  • [6] SIMULATOR ATTACK plus FOR BLACK-BOX ADVERSARIAL ATTACK
    Ji, Yimu
    Ding, Jianyu
    Chen, Zhiyu
    Wu, Fei
    Zhang, Chi
    Sun, Yiming
    Sun, Jing
    Liu, Shangdong
    2022 IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING, ICIP, 2022, : 636 - 640
  • [7] Black-box Adversarial Attacks on Monocular Depth Estimation Using Evolutionary Multi-objective Optimization
    Daimo, Renya
    Suzuki, Takahiro
    Ono, Satoshi
    2021 IEEE INTERNATIONAL CONFERENCE ON SYSTEMS, MAN, AND CYBERNETICS (SMC), 2021, : 3466 - 3471
  • [8] Amora: Black-box Adversarial Morphing Attack
    Wang, Run
    Juefei-Xu, Felix
    Guo, Qing
    Huang, Yihao
    Xie, Xiaofei
    Ma, Lei
    Liu, Yang
    MM '20: PROCEEDINGS OF THE 28TH ACM INTERNATIONAL CONFERENCE ON MULTIMEDIA, 2020, : 1376 - 1385
  • [9] Adversarial Eigen Attack on Black-Box Models
    Zhou, Linjun
    Cui, Peng
    Zhang, Xingxuan
    Jiang, Yinan
    Yang, Shiqiang
    2022 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR 2022), 2022, : 15233 - 15241
  • [10] A black-Box adversarial attack for poisoning clustering
    Cina, Antonio Emanuele
    Torcinovich, Alessandro
    Pelillo, Marcello
    PATTERN RECOGNITION, 2022, 122