Query-efficient black-box ensemble attack via dynamic surrogate weighting

被引:0
作者
Hu, Cong [1 ]
He, Zhichao
Wu, Xiaojun
机构
[1] Jiangnan Univ, Sch Artificial Intelligence & Comp Sci, Wuxi 214122, Jiangsu, Peoples R China
基金
中国国家自然科学基金; 中国博士后科学基金;
关键词
Black-box attack; Ensemble strategies; Deep neural networks; Transferable adversarial example; Image classification;
D O I
10.1016/j.patcog.2024.111263
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
In recent years, deep neural networks (DNNs) have been widely applied across various fields, but the sensitivity of DNNs to adversarial attacks has attracted widespread attention. Existing research has highlighted the potential of ensemble attacks, which blend the strengths of transfer-based and query-based methods, to create highly transferable adversarial examples. It has been noted that simply amalgamating outputs from various models, without considering the gradient variances, can lead to low transferability. Furthermore, employing static model weights or inefficient weight update strategies may contribute to an unnecessary proliferation of query iterations. To address these issues, this paper introduces a novel black-box ensemble attack algorithm (DSWEA) that combines the Ranking Variance Reduced (RVR) ensemble strategy with the Dynamic Surrogate Weighting (DSW) weight update strategy. RVR employs multiple internal iterations within each query to compute and accumulate unbiased gradients, which are then used to update adversarial examples. This optimization of the gradient diminishes the negative impact of excessive gradient discrepancies between models, thereby enhancing the transferability of perturbations. DSW dynamically adjusts the surrogate weights in each query iteration based on model gradient information, guiding the efficient generation of perturbations. We conduct extensive experiments on the ImageNet and CIFAR-10 datasets, involving various models with varying architectures. Our empirical results reveal that our methodology outperforms existing state-of-the-art techniques, showcasing superior efficacy in terms of Attack Success Rate (ASR) and Average Number of Queries (ANQ).
引用
收藏
页数:12
相关论文
共 50 条
  • [41] Understanding the vulnerability of skeleton-based Human Activity Recognition via black-box attack
    Diao, Yunfeng
    Wang, He
    Shao, Tianjia
    Yang, Yongliang
    Zhou, Kun
    Hogg, David
    Wang, Meng
    PATTERN RECOGNITION, 2024, 153
  • [42] A CMA-ES-Based Adversarial Attack on Black-Box Deep Neural Networks
    Kuang, Xiaohui
    Liu, Hongyi
    Wang, Ye
    Zhang, Qikun
    Zhang, Quanxin
    Zheng, Jun
    IEEE ACCESS, 2019, 7 : 172938 - 172947
  • [43] Local Black-box Adversarial Attack based on Random Segmentation Channel
    Xu, Li
    Yang, Zejin
    Guo, Huiting
    Wan, Xu
    Fan, Chunlong
    PROCEEDINGS OF THE 2024 27 TH INTERNATIONAL CONFERENCE ON COMPUTER SUPPORTED COOPERATIVE WORK IN DESIGN, CSCWD 2024, 2024, : 1437 - 1442
  • [44] DIMBA: discretely masked black-box attack in single object tracking
    Xiangyu Yin
    Wenjie Ruan
    Jonathan Fieldsend
    Machine Learning, 2024, 113 : 1705 - 1723
  • [45] Transferable adversarial distribution learning: Query-efficient adversarial attack against large language models
    Dong, Huoyuan
    Dong, Jialiang
    Wan, Shaohua
    Yuan, Shuai
    Guan, Zhitao
    COMPUTERS & SECURITY, 2023, 135
  • [46] Dual stage black-box adversarial attack against vision transformer
    Wang, Fan
    Shao, Mingwen
    Meng, Lingzhuang
    Liu, Fukang
    INTERNATIONAL JOURNAL OF MACHINE LEARNING AND CYBERNETICS, 2024, 15 (08) : 3367 - 3378
  • [47] Black-Box Audio Adversarial Attack Using Particle Swarm Optimization
    Mun, Hyunjun
    Seo, Sunggwan
    Son, Baehoon
    Yun, Joobeom
    IEEE ACCESS, 2022, 10 : 23532 - 23544
  • [48] An adversarial attack on DNN-based black-box object detectors
    Wang, Yajie
    Tan, Yu-an
    Zhang, Wenjiao
    Zhao, Yuhang
    Kuang, Xiaohui
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2020, 161
  • [49] Ensemble adversarial black-box attacks against deep learning systems
    Hang, Jie
    Han, Keji
    Chen, Hui
    Li, Yun
    PATTERN RECOGNITION, 2020, 101
  • [50] A black-box attack on fixed-unitary quantum encryption schemes
    Pilaszewicz, Cezary
    Muth, Lea R.
    Margraf, Marian
    DISCOVER COMPUTING, 2024, 27 (01)