DFDS: Data-Free Dual Substitutes Hard-Label Black-Box Adversarial Attack

被引:0
|
作者
Jiang, Shuliang [1 ]
He, Yusheng [1 ]
Zhang, Rui [1 ]
Kang, Zi [1 ]
Xia, Hui [1 ]
机构
[1] Ocean Univ China, Fac Informat Sci & Engn, Qingdao 266100, Peoples R China
来源
KNOWLEDGE SCIENCE, ENGINEERING AND MANAGEMENT, PT III, KSEM 2024 | 2024年 / 14886卷
基金
中国国家自然科学基金;
关键词
Deep neural networks; Adversarial attack; White-box/black-box attack; Transfer-based adversarial attacks; Adversarial examples;
D O I
10.1007/978-981-97-5498-4_21
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Transfer-based hard-label black-box adversarial attacks, confront challenges in obtaining pertinent proxy datasets and demanding a substantial query volume to the target model without guaranteeing a high attack success rate. To address the challenges, we introduces the techniques of dual substitute model extraction and embedding space adversarial example search, proposing a novel hard-label black-box adversarial attack approach named Data-Free Dual Substitutes Hard-Label Black-Box Adversarial Attack (DFDS). This approach initially trains a generative adversarial network through adversarial training. This training is achieved without relying on proxy datasets, only depending on the hard-label outputs of the target model. Subsequently, it utilizes natural evolution strategy (NES) to conduct embedding space search for constructing the final adversarial examples. The comprehensive experimental results demonstrate that, under the same query volume, DFDS achieves higher attack success rates compared to baseline methods. In comparison to the state-of-the-art mixed-mechanism hard-label black-box attack approach DFMS-HL, DFDS exhibits significant improvements across the SVHN, CIFAR-10, and CIFAR-100 datasets. Significantly, in the targeted attack scenario on the CIFAR-10 dataset, the success rate reaches 76.59%, representing the highest enhancement of 21.99%.
引用
收藏
页码:274 / 285
页数:12
相关论文
共 50 条
  • [41] Universal Black-Box Adversarial Attack on Deep Learning for Specific Emitter Identification
    Chen, Kailun
    Zhang, Yibin
    Cai, Zhenxin
    Wang, Yu
    Ye, Chen
    Lin, Yun
    Gui, Guan
    2024 IEEE 99TH VEHICULAR TECHNOLOGY CONFERENCE, VTC2024-SPRING, 2024,
  • [42] Attention-guided transformation-invariant attack for black-box adversarial examples
    Zhu, Jiaqi
    Dai, Feng
    Yu, Lingyun
    Xie, Hongtao
    Wang, Lidong
    Wu, Bo
    Zhang, Yongdong
    INTERNATIONAL JOURNAL OF INTELLIGENT SYSTEMS, 2022, 37 (05) : 3142 - 3165
  • [43] Coreset Learning-Based Sparse Black-Box Adversarial Attack for Video Recognition
    Chen, Jiefu
    Chen, Tong
    Xu, Xing
    Zhang, Jingran
    Yang, Yang
    Shen, Heng Tao
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 1547 - 1560
  • [44] An Empirical Study of Fully Black-Box and Universal Adversarial Attack for SAR Target Recognition
    Peng, Bowen
    Peng, Bo
    Yong, Shaowei
    Liu, Li
    REMOTE SENSING, 2022, 14 (16)
  • [45] SSQLi: A Black-Box Adversarial Attack Method for SQL Injection Based on Reinforcement Learning
    Guan, Yuting
    He, Junjiang
    Li, Tao
    Zhao, Hui
    Ma, Baoqiang
    FUTURE INTERNET, 2023, 15 (04):
  • [46] A CMA-ES-Based Adversarial Attack on Black-Box Deep Neural Networks
    Kuang, Xiaohui
    Liu, Hongyi
    Wang, Ye
    Zhang, Qikun
    Zhang, Quanxin
    Zheng, Jun
    IEEE ACCESS, 2019, 7 : 172938 - 172947
  • [47] Disappeared Face: A Physical Adversarial Attack Method on Black-Box Face Detection Models
    Zhou, Chuan
    Jing, Huiyun
    He, Xin
    Wang, Liming
    Chen, Kai
    Ma, Duohe
    INFORMATION AND COMMUNICATIONS SECURITY (ICICS 2021), PT I, 2021, 12918 : 119 - 135
  • [48] FLDATN: Black-Box Attack for Face Liveness Detection Based on Adversarial Transformation Network
    Peng, Yali
    Liu, Jianbo
    Long, Min
    Peng, Fei
    INTERNATIONAL JOURNAL OF INTELLIGENT SYSTEMS, 2024, 2024
  • [49] Black-box Adversarial Attack Against Road Sign Recognition Model via PSO
    Chen J.-Y.
    Chen Z.-Q.
    Zheng H.-B.
    Shen S.-J.
    Su M.-M.
    Ruan Jian Xue Bao/Journal of Software, 2020, 31 (09): : 2785 - 2801
  • [50] A black-box adversarial attack strategy with adjustable sparsity and generalizability for deep image classifiers
    Ghosh, Arka
    Mullick, Sankha Subhra
    Datta, Shounak
    Das, Swagatam
    Das, Asit Kr
    Mallipeddi, Rammohan
    PATTERN RECOGNITION, 2022, 122