Adaptive hyperparameter optimization for black-box adversarial attack

被引:0
作者
Zhenyu Guan
Lixin Zhang
Bohan Huang
Bihe Zhao
Song Bian
机构
[1] Beihang University,School of Cyber Science and Technology
来源
International Journal of Information Security | 2023年 / 22卷
关键词
Deep learning; Adversarial attack; Reinforcement learning; Hyperparameter optimization;
D O I
暂无
中图分类号
学科分类号
摘要
The study of adversarial attacks is crucial in the design of robust neural network models. In this work, we propose a hyperparameter optimization framework for black-box adversarial attacks. We observe that hyperparameters are extremely important to enhance the query efficiency of many black-box adversarial attack methods. Hence, we propose an adaptive hyperparameter tuning framework such that, in each query iteration, the attacker can adaptively selects the hyperparameter configuration based on the feedback from the victim to improve the attack success rate and query efficiency of the attack algorithm. The experiment results show, by adaptively tuning the attack hyperparameters, our technique outperforms the original algorithm, where the query efficiency is improved by 33.63% on the NES algorithm for untargeted attacks, 44.47% on the Bandits algorithm for untargeted attacks, and 32.24% improvement on the Bandits algorithm for targeted attacks.
引用
收藏
页码:1765 / 1779
页数:14
相关论文
共 42 条
[1]  
Krizhevsky A(2017)Imagenet classification with deep convolutional neural networks Commun. ACM 60 84-90
[2]  
Sutskever I(2012)Deep neural networks for acoustic modeling in speech recognition: the shared views of four research groups IEEE Signal Process. Mag. 29 82-97
[3]  
Hinton GE(2019)Autozoom: autoencoder-based zeroth order optimization method for attacking black-box neural networks Proc. AAAI Conf. Artif. Intell. 33 742-749
[4]  
Hinton G(2019)Improving black-box adversarial attacks with a transfer-based prior Adv. Neural Inf. Process. Syst. 32 250-65
[5]  
Deng L(2018)Generative adversarial networks: an overview IEEE Signal Process. Mag. 35 53-533
[6]  
Yu D(2015)Human-level control through deep reinforcement learning Nature 518 529-undefined
[7]  
Dahl GE(undefined)undefined undefined undefined undefined-undefined
[8]  
Mohamed A-R(undefined)undefined undefined undefined undefined-undefined
[9]  
Jaitly N(undefined)undefined undefined undefined undefined-undefined
[10]  
Senior A(undefined)undefined undefined undefined undefined-undefined