A Stable and Efficient Data-Free Model Attack With Label-Noise Data Generation

被引:0
|
作者
Zhang, Zhixuan [1 ]
Zheng, Xingjian [2 ]
Qing, Linbo [1 ]
Liu, Qi [3 ]
Wang, Pingyu [4 ]
Liu, Yu [4 ]
Liao, Jiyang [4 ]
机构
[1] Sichuan Univ, Sch Cyber Sci & Engn, Chengdu 610207, Peoples R China
[2] Frost Drill Intellectual Software Pte Ltd, Int Plaza, Singapore 079903, Singapore
[3] South China Univ Technol, Sch Future Technol, Guangzhou 511442, Peoples R China
[4] Sichuan Univ, Coll Elect & Informat Engn, Chengdu 610065, Peoples R China
基金
中国国家自然科学基金;
关键词
Training; Closed box; Generators; Data models; Data collection; Adaptation models; Diversity methods; Cloning; Glass box; Computational modeling; Deep neural network; data-free; adversarial examples; closed-box attack;
D O I
10.1109/TIFS.2025.3550066
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The objective of a data-free closed-box adversarial attack is to attack a victim model without using internal information, training datasets or semantically similar substitute datasets. Concerned about stricter attack scenarios, recent studies have tried employing generative networks to synthesize data for training substitute models. Nevertheless, these approaches concurrently encounter challenges associated with unstable training and diminished attack efficiency. In this paper, we propose a novel query-efficient data-free closed-box adversarial attack method. To mitigate unstable training, for the first time, we directly manipulate the intermediate-layer feature of a generator without relying on any substitute models. Specifically, a label noise-based generation module is created to enhance the intra-class patterns by incorporating partial historical information during the learning process. Additionally, we present a feature-disturbed diversity generation method to augment the inter-class distance. Meanwhile, we propose an adaptive intra-class attack strategy to heighten attack capability within a limited query budget. In this strategy, entropy-based distance is utilized to characterize the relative information from model outputs, while positive classes and negative samples are used to enhance low attack efficiency. The comprehensive experiments conducted on six datasets demonstrate the superior performance of our method compared to six state-of-the-art data-free closed-box competitors in both label-only and probability-only attack scenarios. Intriguingly, our method can realize the highest attack success rate on the online Microsoft Azure model under an extremely low query budget. Additionally, the proposed approach not only achieves more stable training but also significantly reduces the query count for a more balanced data generation. Furthermore, our method can maintain the best performance under the existing defense models and a limited query budget.
引用
收藏
页码:3131 / 3145
页数:15
相关论文
共 50 条
  • [21] Data-Free Backdoor Removal Based on Channel Lipschitzness
    Zheng, Runkai
    Tang, Rongjun
    Li, Jianze
    Liu, Li
    COMPUTER VISION - ECCV 2022, PT V, 2022, 13665 : 175 - 191
  • [22] Data-Free Ensemble Knowledge Distillation for Privacy-conscious Multimedia Model Compression
    Hao, Zhiwei
    Luo, Yong
    Hu, Han
    An, Jianping
    Wen, Yonggang
    PROCEEDINGS OF THE 29TH ACM INTERNATIONAL CONFERENCE ON MULTIMEDIA, MM 2021, 2021, : 1803 - 1811
  • [23] Double-Generators Network for Data-Free Knowledge Distillation
    Zhang J.
    Ju J.
    Ren Y.
    Jisuanji Yanjiu yu Fazhan/Computer Research and Development, 2023, 60 (07): : 1615 - 1627
  • [24] Latent Coreset Sampling based Data-Free Continual Learning
    Wang, Zhuoyi
    Li, Dingcheng
    Li, Ping
    PROCEEDINGS OF THE 31ST ACM INTERNATIONAL CONFERENCE ON INFORMATION AND KNOWLEDGE MANAGEMENT, CIKM 2022, 2022, : 2078 - 2087
  • [25] Prototypical Metric Segment Anything Model for Data-Free Few-Shot Semantic Segmentation
    Jiang, Zhiyu
    Yuan, Ye
    Yuan, Yuan
    IEEE SIGNAL PROCESSING LETTERS, 2024, 31 : 2800 - 2804
  • [26] Data Generation Approach Based on Data Model Fusion: An Application for Rolling Bearings Fault Diagnosis With Small Samples
    Zhu, Yonghuai
    Cheng, Jiangfeng
    Liu, Zhifeng
    Zou, Xiaofu
    Cheng, Qiang
    Xu, Hui
    Wang, Yong
    Tao, Fei
    IEEE TRANSACTIONS ON INSTRUMENTATION AND MEASUREMENT, 2025, 74
  • [27] Data-Free Solution of Electromagnetic PDEs Using Neural Networks and Extension to Transfer Learning
    Bhardwaj, Shubhendu
    Gaire, Pawan
    IEEE TRANSACTIONS ON ANTENNAS AND PROPAGATION, 2022, 70 (07) : 5179 - 5188
  • [28] Enhancing Tabular Data Generation With Dual-Scale Noise Modeling
    Zhang, Xiaorong
    Li, Fei
    Hu, Xuting
    IEEE ACCESS, 2025, 13 : 48643 - 48655
  • [29] Data-Free Low-Bit Quantization for Remote Sensing Object Detection
    Zhang, Ruiyan
    Jiang, Xiujie
    An, Junshe
    Cui, Tianshu
    IEEE GEOSCIENCE AND REMOTE SENSING LETTERS, 2022, 19
  • [30] Efficient Model-Relational Data Management: Challenges and Opportunities
    Sanca, Viktor
    Ailamaki, Anastasia
    IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 2024, 36 (12) : 7399 - 7409