Black-box adversarial sample generation based on differential evolution

被引:30
作者
Lin, Junyu [1 ,2 ]
Xu, Lei [1 ,2 ]
Liu, Yingqi [3 ]
Zhang, Xiangyu [3 ]
机构
[1] Nanjing Univ, State Key Lab Novel Software Technol, Nanjing, Peoples R China
[2] Nanjing Univ, Dept Comp Sci & Technol, Nanjing, Peoples R China
[3] Purdue Univ, Dept Comp Sci, W Lafayette, IN 47907 USA
关键词
Adversarial samples; Differential evolution; Black-box testing; Deep Neural Network;
D O I
10.1016/j.jss.2020.110767
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Deep Neural Networks (DNNs) are being used in various daily tasks such as object detection, speech processing, and machine translation. However, it is known that DNNs suffer from robustness problems - perturbed inputs called adversarial samples leading to misbehaviors of DNNs. In this paper, we propose a black-box technique called Black-box Momentum Iterative Fast Gradient Sign Method (BMI-FGSM) to test the robustness of DNN models. The technique does not require any knowledge of the structure or weights of the target DNN. Compared to existing white-box testing techniques that require accessing model internal information such as gradients, our technique approximates gradients through Differential Evolution and uses approximated gradients to construct adversarial samples. Experimental results show that our technique can achieve 100% success in generating adversarial samples to trigger misclassification, and over 95% success in generating samples to trigger misclassification to a specific target output label. It also demonstrates better perturbation distance and better transferability. Compared to the state-of-the-art black-box technique, our technique is more efficient. Furthermore, we conduct testing on the commercial Aliyun API and successfully trigger its misbehavior within a limited number of queries, demonstrating the feasibility of real-world black-box attack. (C) 2020 Elsevier Inc. All rights reserved.
引用
收藏
页数:11
相关论文
共 50 条
  • [31] GENERATION OF ADVERSARIAL EXAMPLES USING ADAPTIVE DIFFERENTIAL EVOLUTION
    Kushida, Jun-ichi
    Hara, Akira
    Takahama, Tetsuyuki
    [J]. INTERNATIONAL JOURNAL OF INNOVATIVE COMPUTING INFORMATION AND CONTROL, 2020, 16 (01): : 405 - 414
  • [32] Empirical Comparison of Black-box Test Case Generation Tools for RESTful APIs
    Corradini, Davide
    Zampieri, Amedeo
    Pasqua, Michele
    Ceccato, Mariano
    [J]. IEEE 21ST INTERNATIONAL WORKING CONFERENCE ON SOURCE CODE ANALYSIS AND MANIPULATION (SCAM 2021), 2021, : 226 - 236
  • [33] Improved black-box attack based on query and perturbation distribution
    Zhao, Weiwei
    Zeng, Zhigang
    [J]. 2021 13TH INTERNATIONAL CONFERENCE ON ADVANCED COMPUTATIONAL INTELLIGENCE (ICACI), 2021, : 117 - 125
  • [34] Black-Box for Blockchain Parameters Adjustment
    Amelin, Vladislav
    Gatiyatullin, Ernest
    Romanov, Nikita
    Samarkhanov, Ratmir
    Vasilyev, Robert
    Yanovich, Yury
    [J]. IEEE ACCESS, 2022, 10 : 101795 - 101802
  • [35] Information gain of black-box testing
    Yang, Linmin
    Dang, Zhe
    Fischer, Thomas R.
    [J]. FORMAL ASPECTS OF COMPUTING, 2011, 23 (04) : 513 - 539
  • [36] Adjust-free adversarial example generation in speech recognition using evolutionary multi-objective optimization under black-box condition
    Shoma Ishida
    Satoshi Ono
    [J]. Artificial Life and Robotics, 2021, 26 : 243 - 249
  • [37] Adjust-free adversarial example generation in speech recognition using evolutionary multi-objective optimization under black-box condition
    Ishida, Shoma
    Ono, Satoshi
    [J]. ARTIFICIAL LIFE AND ROBOTICS, 2021, 26 (02) : 243 - 249
  • [38] A Constraint-Based Framework for Test Case Generation in Method-Level Black-Box Unit Testing
    Chang, Chi-Kuang
    Lin, Nai-Wei
    [J]. JOURNAL OF INFORMATION SCIENCE AND ENGINEERING, 2016, 32 (02) : 365 - 387
  • [39] Black-Box String Test Case Generation through a Multi-Objective Optimization
    Shahbazi, Ali
    Miller, James
    [J]. IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 2016, 42 (04) : 361 - 378
  • [40] Pixle: a fast and effective black-box attack based on rearranging pixels
    Pomponi, Jary
    Scardapane, Simone
    Uncini, Aurelio
    [J]. 2022 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS (IJCNN), 2022,