A Stable and Efficient Data-Free Model Attack With Label-Noise Data Generation

被引:0
|
作者
Zhang, Zhixuan [1 ]
Zheng, Xingjian [2 ]
Qing, Linbo [1 ]
Liu, Qi [3 ]
Wang, Pingyu [4 ]
Liu, Yu [4 ]
Liao, Jiyang [4 ]
机构
[1] Sichuan Univ, Sch Cyber Sci & Engn, Chengdu 610207, Peoples R China
[2] Frost Drill Intellectual Software Pte Ltd, Int Plaza, Singapore 079903, Singapore
[3] South China Univ Technol, Sch Future Technol, Guangzhou 511442, Peoples R China
[4] Sichuan Univ, Coll Elect & Informat Engn, Chengdu 610065, Peoples R China
基金
中国国家自然科学基金;
关键词
Training; Closed box; Generators; Data models; Data collection; Adaptation models; Diversity methods; Cloning; Glass box; Computational modeling; Deep neural network; data-free; adversarial examples; closed-box attack;
D O I
10.1109/TIFS.2025.3550066
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The objective of a data-free closed-box adversarial attack is to attack a victim model without using internal information, training datasets or semantically similar substitute datasets. Concerned about stricter attack scenarios, recent studies have tried employing generative networks to synthesize data for training substitute models. Nevertheless, these approaches concurrently encounter challenges associated with unstable training and diminished attack efficiency. In this paper, we propose a novel query-efficient data-free closed-box adversarial attack method. To mitigate unstable training, for the first time, we directly manipulate the intermediate-layer feature of a generator without relying on any substitute models. Specifically, a label noise-based generation module is created to enhance the intra-class patterns by incorporating partial historical information during the learning process. Additionally, we present a feature-disturbed diversity generation method to augment the inter-class distance. Meanwhile, we propose an adaptive intra-class attack strategy to heighten attack capability within a limited query budget. In this strategy, entropy-based distance is utilized to characterize the relative information from model outputs, while positive classes and negative samples are used to enhance low attack efficiency. The comprehensive experiments conducted on six datasets demonstrate the superior performance of our method compared to six state-of-the-art data-free closed-box competitors in both label-only and probability-only attack scenarios. Intriguingly, our method can realize the highest attack success rate on the online Microsoft Azure model under an extremely low query budget. Additionally, the proposed approach not only achieves more stable training but also significantly reduces the query count for a more balanced data generation. Furthermore, our method can maintain the best performance under the existing defense models and a limited query budget.
引用
收藏
页码:3131 / 3145
页数:15
相关论文
共 50 条
  • [1] Effectively Improving Data Diversity of Substitute Training for Data-Free Black-Box Attack
    Wei, Yang
    Ma, Zhuo
    Ma, Zhuoran
    Qin, Zhan
    Liu, Yang
    Xiao, Bin
    Bi, Xiuli
    Ma, Jianfeng
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2024, 21 (04) : 4206 - 4219
  • [2] Dynamic Routing and Knowledge Re-Learning for Data-Free Black-Box Attack
    Qian, Xuelin
    Wang, Wenxuan
    Jiang, Yu-Gang
    Xue, Xiangyang
    Fu, Yanwei
    IEEE TRANSACTIONS ON PATTERN ANALYSIS AND MACHINE INTELLIGENCE, 2025, 47 (01) : 486 - 501
  • [3] Latent Code Augmentation Based on Stable Diffusion for Data-Free Substitute Attacks
    Shao, Mingwen
    Meng, Lingzhuang
    Qiao, Yuanjian
    Zhang, Lixu
    Zuo, Wangmeng
    IEEE TRANSACTIONS ON NEURAL NETWORKS AND LEARNING SYSTEMS, 2025,
  • [4] FedGhost: Data-Free Model Poisoning Enhancement in Federated Learning
    Ma, Zhuoran
    Huang, Xinyi
    Wang, Zhuzhu
    Qin, Zhan
    Wang, Xiangyu
    Ma, Jianfeng
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2025, 20 : 2096 - 2108
  • [5] Learning to Generate Diverse Data From a Temporal Perspective for Data-Free Quantization
    Luo, Hui
    Zhang, Shuhai
    Zhuang, Zhuangwei
    Mai, Jiajie
    Tan, Mingkui
    Zhang, Jianlin
    IEEE TRANSACTIONS ON CIRCUITS AND SYSTEMS FOR VIDEO TECHNOLOGY, 2024, 34 (10) : 9484 - 9498
  • [6] DQDG: Data-Free Quantization With Dual Generators for Keyword Spotting
    Xu, Xinbiao
    Ma, Liyan
    Jia, Fan
    Zeng, Tieyong
    IEEE SIGNAL PROCESSING LETTERS, 2024, 31 : 1540 - 1544
  • [7] DFDS: Data-Free Dual Substitutes Hard-Label Black-Box Adversarial Attack
    Jiang, Shuliang
    He, Yusheng
    Zhang, Rui
    Kang, Zi
    Xia, Hui
    KNOWLEDGE SCIENCE, ENGINEERING AND MANAGEMENT, PT III, KSEM 2024, 2024, 14886 : 274 - 285
  • [8] Exploring and Exploiting Data-Free Model Stealing
    Hong, Chi
    Huang, Jiyue
    Birke, Robert
    Chen, Lydia Y.
    MACHINE LEARNING AND KNOWLEDGE DISCOVERY IN DATABASES: RESEARCH TRACK, ECML PKDD 2023, PT V, 2023, 14173 : 20 - 35
  • [9] From Data to Optimization: Data-Free Deep Incremental Hashing With Data Disambiguation and Adaptive Proxies
    Su, Qinghang
    Wu, Dayan
    Wu, Chenming
    Li, Bo
    Wang, Weiping
    IEEE TRANSACTIONS ON CIRCUITS AND SYSTEMS FOR VIDEO TECHNOLOGY, 2024, 34 (07) : 6576 - 6589
  • [10] Unpacking the Gap Box Against Data-Free Knowledge Distillation
    Wang, Yang
    Qian, Biao
    Liu, Haipeng
    Rui, Yong
    Wang, Meng
    IEEE TRANSACTIONS ON PATTERN ANALYSIS AND MACHINE INTELLIGENCE, 2024, 46 (09) : 6280 - 6291