Adaptive hyperparameter optimization for black-box adversarial attack

被引:0
作者
Zhenyu Guan
Lixin Zhang
Bohan Huang
Bihe Zhao
Song Bian
机构
[1] Beihang University,School of Cyber Science and Technology
来源
International Journal of Information Security | 2023年 / 22卷
关键词
Deep learning; Adversarial attack; Reinforcement learning; Hyperparameter optimization;
D O I
暂无
中图分类号
学科分类号
摘要
The study of adversarial attacks is crucial in the design of robust neural network models. In this work, we propose a hyperparameter optimization framework for black-box adversarial attacks. We observe that hyperparameters are extremely important to enhance the query efficiency of many black-box adversarial attack methods. Hence, we propose an adaptive hyperparameter tuning framework such that, in each query iteration, the attacker can adaptively selects the hyperparameter configuration based on the feedback from the victim to improve the attack success rate and query efficiency of the attack algorithm. The experiment results show, by adaptively tuning the attack hyperparameters, our technique outperforms the original algorithm, where the query efficiency is improved by 33.63% on the NES algorithm for untargeted attacks, 44.47% on the Bandits algorithm for untargeted attacks, and 32.24% improvement on the Bandits algorithm for targeted attacks.
引用
收藏
页码:1765 / 1779
页数:14
相关论文
共 50 条
  • [31] FLDATN: Black-Box Attack for Face Liveness Detection Based on Adversarial Transformation Network
    Peng, Yali
    Liu, Jianbo
    Long, Min
    Peng, Fei
    INTERNATIONAL JOURNAL OF INTELLIGENT SYSTEMS, 2024, 2024
  • [32] Disappeared Face: A Physical Adversarial Attack Method on Black-Box Face Detection Models
    Zhou, Chuan
    Jing, Huiyun
    He, Xin
    Wang, Liming
    Chen, Kai
    Ma, Duohe
    INFORMATION AND COMMUNICATIONS SECURITY (ICICS 2021), PT I, 2021, 12918 : 119 - 135
  • [33] BFS2Adv: Black-box adversarial attack towards hard-to-attack short texts
    Han, Xu
    Li, Qiang
    Cao, Hongbo
    Han, Lei
    Wang, Bin
    Bao, Xuhua
    Han, Yufei
    Wang, Wei
    COMPUTERS & SECURITY, 2024, 141
  • [34] FABRICATE-VANISH: AN EFFECTIVE AND TRANSFERABLE BLACK-BOX ADVERSARIAL ATTACK INCORPORATING FEATURE DISTORTION
    Lu, Yantao
    Du, Xueying
    Sun, Bingkun
    Ren, Haining
    Velipasalar, Senem
    2021 IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING (ICIP), 2021, : 809 - 813
  • [35] A New Meta-learning-based Black-box Adversarial Attack: SA-CC
    Ding, Jianyu
    Chen, Zhiyu
    2022 34TH CHINESE CONTROL AND DECISION CONFERENCE, CCDC, 2022, : 4326 - 4331
  • [36] Object-Aware Transfer-Based Black-Box Adversarial Attack on Object Detector
    Leng, Zhuo
    Cheng, Zesen
    Wei, Pengxu
    Chen, Jie
    PATTERN RECOGNITION AND COMPUTER VISION, PRCV 2023, PT XII, 2024, 14436 : 278 - 289
  • [37] Exploring the vulnerability of black-box adversarial attack on prompt-based learning in language models
    Zihao Tan
    Qingliang Chen
    Wenbin Zhu
    Yongjian Huang
    Chen Liang
    Neural Computing and Applications, 2025, 37 (3) : 1457 - 1473
  • [38] A Black-Box Adversarial Attack Method via Nesterov Accelerated Gradient and Rewiring Towards Attacking Graph Neural Networks
    Zhao, Shu
    Wang, Wenyu
    Du, Ziwei
    Chen, Jie
    Duan, Zhen
    IEEE TRANSACTIONS ON BIG DATA, 2023, 9 (06) : 1586 - 1597
  • [39] Black-box attacks on dynamic graphs via adversarial topology perturbations
    Tao, Haicheng
    Cao, Jie
    Chen, Lei
    Sun, Hongliang
    Shi, Yong
    Zhu, Xingquan
    NEURAL NETWORKS, 2024, 171 : 308 - 319
  • [40] Black-box adversarial attacks by manipulating image attributes
    Wei, Xingxing
    Guo, Ying
    Li, Bo
    INFORMATION SCIENCES, 2021, 550 : 285 - 296