A Stable and Efficient Data-Free Model Attack With Label-Noise Data Generation

被引:0
|
作者
Zhang, Zhixuan [1 ]
Zheng, Xingjian [2 ]
Qing, Linbo [1 ]
Liu, Qi [3 ]
Wang, Pingyu [4 ]
Liu, Yu [4 ]
Liao, Jiyang [4 ]
机构
[1] Sichuan Univ, Sch Cyber Sci & Engn, Chengdu 610207, Peoples R China
[2] Frost Drill Intellectual Software Pte Ltd, Int Plaza, Singapore 079903, Singapore
[3] South China Univ Technol, Sch Future Technol, Guangzhou 511442, Peoples R China
[4] Sichuan Univ, Coll Elect & Informat Engn, Chengdu 610065, Peoples R China
基金
中国国家自然科学基金;
关键词
Training; Closed box; Generators; Data models; Data collection; Adaptation models; Diversity methods; Cloning; Glass box; Computational modeling; Deep neural network; data-free; adversarial examples; closed-box attack;
D O I
10.1109/TIFS.2025.3550066
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The objective of a data-free closed-box adversarial attack is to attack a victim model without using internal information, training datasets or semantically similar substitute datasets. Concerned about stricter attack scenarios, recent studies have tried employing generative networks to synthesize data for training substitute models. Nevertheless, these approaches concurrently encounter challenges associated with unstable training and diminished attack efficiency. In this paper, we propose a novel query-efficient data-free closed-box adversarial attack method. To mitigate unstable training, for the first time, we directly manipulate the intermediate-layer feature of a generator without relying on any substitute models. Specifically, a label noise-based generation module is created to enhance the intra-class patterns by incorporating partial historical information during the learning process. Additionally, we present a feature-disturbed diversity generation method to augment the inter-class distance. Meanwhile, we propose an adaptive intra-class attack strategy to heighten attack capability within a limited query budget. In this strategy, entropy-based distance is utilized to characterize the relative information from model outputs, while positive classes and negative samples are used to enhance low attack efficiency. The comprehensive experiments conducted on six datasets demonstrate the superior performance of our method compared to six state-of-the-art data-free closed-box competitors in both label-only and probability-only attack scenarios. Intriguingly, our method can realize the highest attack success rate on the online Microsoft Azure model under an extremely low query budget. Additionally, the proposed approach not only achieves more stable training but also significantly reduces the query count for a more balanced data generation. Furthermore, our method can maintain the best performance under the existing defense models and a limited query budget.
引用
收藏
页码:3131 / 3145
页数:15
相关论文
共 50 条
  • [41] DHBE: Data-free Holistic Backdoor Erasing in Deep Neural Networks via Restricted Adversarial Distillation
    Yan, Zhicong
    Li, Shenghong
    Zhao, Ruijie
    Tian, Yuan
    Zhao, Yuanyuan
    PROCEEDINGS OF THE 2023 ACM ASIA CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, ASIA CCS 2023, 2023, : 731 - 745
  • [42] An Integrated Missing-Data Tolerant Model for Probabilistic PV Power Generation Forecasting
    Li, Qiaoqiao
    Xu, Yan
    Chew, Benjamin Si Hao
    Ding, Hongyuan
    Zhao, Guopeng
    IEEE TRANSACTIONS ON POWER SYSTEMS, 2022, 37 (06) : 4447 - 4459
  • [43] Toward Memory-Efficient and Interpretable Factorization Machines via Data and Model Binarization
    Geng, Yu
    Lan, Liang
    Cheung, William K.
    IEEE ACCESS, 2023, 11 : 128633 - 128643
  • [44] R-DFCIL: Relation-Guided Representation Learning for Data-Free Class Incremental Learning
    Gao, Qiankun
    Zhao, Chen
    Ghanem, Bernard
    Zhang, Jian
    COMPUTER VISION, ECCV 2022, PT XXIII, 2022, 13683 : 423 - 439
  • [45] An Ensemble Data-Model-Label Three-Level Regularization Framework for Imbalanced Intelligent Fault Diagnosis
    Luo, Yixiong
    Shi, Jianhua
    Tan, Jinbiao
    Ren, Zijie
    Wan, Jiafu
    Safran, Mejdl
    Alqahtani, Salman A.
    IEEE TRANSACTIONS ON RELIABILITY, 2024, : 1 - 13
  • [46] A mechanics-based data-free Problem Independent Machine Learning (PIML) model for large-scale structural analysis and design optimization
    Huang, Mengcheng
    Liu, Chang
    Guo, Yilin
    Zhang, Linfeng
    Du, Zongliang
    Guo, Xu
    JOURNAL OF THE MECHANICS AND PHYSICS OF SOLIDS, 2024, 193
  • [47] Secure and Efficient Federated Learning Against Model Poisoning Attacks in Horizontal and Vertical Data Partitioning
    Yu, Chong
    Meng, Zhenyu
    Zhang, Wenmiao
    Lei, Lei
    Ni, Jianbing
    Zhang, Kuan
    Zhao, Hai
    IEEE TRANSACTIONS ON NEURAL NETWORKS AND LEARNING SYSTEMS, 2024,
  • [48] A physics-informed neural network enhanced importance sampling (PINN-IS) for data-free reliability analysis
    Roy, Atin
    Chatterjee, Tanmoy
    Adhikari, Sondipon
    PROBABILISTIC ENGINEERING MECHANICS, 2024, 78
  • [49] Subject-Level Membership Inference Attack via Data Augmentation and Model Discrepancy
    Liu, Yimin
    Jiang, Peng
    Zhu, Liehuang
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2023, 18 : 5848 - 5859
  • [50] An Efficient Privacy-Enhancing Cross-Silo Federated Learning and Applications for False Data Injection Attack Detection in Smart Grids
    Tran, Hong-Yen
    Hu, Jiankun
    Yin, Xuefei
    Pota, Hemanshu R.
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2023, 18 : 2538 - 2552