Parsimonious Black-Box Adversarial Attacks via Efficient Combinatorial Optimization
arXiv:1905.06635
Abstract
Solving for adversarial examples with projected gradient descent has been demonstrated to be highly effective in fooling the neural network based classifiers. However, in the black-box setting, the attacker is limited only to the query access to the network and solving for a successful adversarial example becomes much more difficult. To this end, recent methods aim at estimating the true gradient signal based on the input queries but at the cost of excessive queries. We propose an efficient discrete surrogate to the optimization problem which does not require estimating the gradient and consequently becomes free of the first order update hyperparameters to tune. Our experiments on Cifar-10 and ImageNet show the state of the art black-box attack performance with significant reduction in the required queries compared to a number of recently proposed methods. The source code is available at https://github.com/snu-mllab/parsimonious-blackbox-attack.
Accepted and to appear at ICML 2019
Cited by in corpus (24)
- Black-box Adversarial Attacks with Bayesian Optimization
- A Survey of Black-Box Adversarial Attacks on Computer Vision Models
- Towards Visual Distortion in Black-Box Attacks
- Yet another but more efficient black-box adversarial attack: tiling and evolution strategies
- AdvFlow: Inconspicuous Black-box Adversarial Attacks using Normalizing Flows
- Hybrid Batch Attacks: Finding Black-box Adversarial Examples with Limited Queries
- Searching for a Search Method: Benchmarking Search Algorithms for Generating NLP Adversarial Examples
- Adversarial Robustness by Design through Analog Computing and Synthetic Gradients
- Boosting Black-Box Attack with Partially Transferred Conditional Adversarial Distribution
- RayS: A Ray Searching Method for Hard-label Adversarial Attack
- Random Noise Defense Against Query-Based Black-Box Attacks
- Efficient Combinatorial Optimization for Word-level Adversarial Textual Attack
- DeepSearch: A Simple and Effective Blackbox Attack for Deep Neural Networks
- Switching Transferable Gradient Directions for Query-Efficient Black-Box Adversarial Attacks
- You Only Query Once: Effective Black Box Adversarial Attacks with Minimal Repeated Queries
- Meta-Learning the Search Distribution of Black-Box Random Search Based Adversarial Attacks
- On Procedural Adversarial Noise Attack And Defense
- Improving Robustness of Malware Classifiers using Adversarial Strings Generated from Perturbed Latent Representations
- Simple and Efficient Hard Label Black-box Adversarial Attacks in Low Query Budget Regimes
- EvoBA: An Evolution Strategy as a Strong Baseline forBlack-Box Adversarial Attacks
- A Black-box Adversarial Attack Strategy with Adjustable Sparsity and Generalizability for Deep Image Classifiers
- Luring of transferable adversarial perturbations in the black-box paradigm
- Gaussian MRF Covariance Modeling for Efficient Black-Box Adversarial Attacks
- A Model-Based Derivative-Free Approach to Black-Box Adversarial Examples: BOBYQA