arrow
返回

Query-efficient black-box ensemble attack via dynamic surrogate weighting

delete2025-05-01
delete0
PRE
AI
C
Cong Hu *
Z
Zhichao He
X
Xiao‐Jun Wu
DOI:10.1016/j.patcog.2024.111263delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
In recent years, deep neural networks (DNNs) have been widely applied across various fields, but the sensitivity of DNNs to adversarial attacks has attracted widespread attention. Existing research has highlighted the potential of ensemble attacks, which blend the strengths of transfer-based and query-based methods, to create highly transferable adversarial examples. It has been noted that simply amalgamating outputs from various models, without considering the gradient variances, can lead to low transferability. Furthermore, employing static model weights or inefficient weight update strategies may contribute to an unnecessary proliferation of query iterations. To address these issues, this paper introduces a novel black-box ensemble attack algorithm (DSWEA) that combines the Ranking Variance Reduced (RVR) ensemble strategy with the Dynamic Surrogate Weighting (DSW) weight update strategy. RVR employs multiple internal iterations within each query to compute and accumulate unbiased gradients, which are then used to update adversarial examples. This optimization of the gradient diminishes the negative impact of excessive gradient discrepancies between models, thereby enhancing the transferability of perturbations. DSW dynamically adjusts the surrogate weights in each query iteration based on model gradient information, guiding the efficient generation of perturbations. We conduct extensive experiments on the ImageNet and CIFAR-10 datasets, involving various models with varying architectures. Our empirical results reveal that our methodology outperforms existing state-of-the-art techniques, showcasing superior efficacy in terms of Attack Success Rate (ASR) and Average Number of Queries (ANQ).
Keyword:
Black-box attack
Ensemble strategies
Deep neural networks
Transferable adversarial example
Image classification

期刊

Pattern Recognition 封面图
Pattern Recognition
IF:
7.6
论文数:
1.3W
被引数:
4.5W

机构

暂无机构信息
引用论文

引用论文

Preschool Children’s Reasoning about Sound from an Inferential-Representational Approach
err2021-04-12
err0
errOAAI
errLeticia Gallegos-Cázares; Fernando Flores-Camacho; Elena Calderón-Canales
err分享
err收藏
SMGEA: A New Ensemble Adversarial Attack Powered by Long-Term Gradient Memories
err2022-03-01
err15
PREAI
errChe, Zhaohui; Borji, Ali; Zhai, Guangtao; Ling, Suiyi; Li, Jing; Min, Xiongkuo; Guo, Guodong; Le Callet, Patrick
err分享
err收藏
err分享
err收藏
Multi-feature sparse similar representation for person identification
err2022-12-01
err5
PREAI
errYang, Meng; Liao, Lei; Ke, Kangyin; Gao, Guangwei
err分享
err收藏
Systemic administration of autologous, alloactivated helper-enriched lymphocytes to patients with metastatic melanoma of the lung
err1986-03-01
err0
errOAAI
errAndrea Balsari; Raffaele Marolda; Carlo Gambacorti-Passerini; Gianalfredo Sciorelli; Gabriella Tona; Elisabetta Cosulich; Donatella Taramelli; Giuseppe Fossati; Giorgio Parmiani; Natale Cascinelli
err分享
err收藏
Dental Restorative Materials for Elderly Populations
err2021-03-08
err0
errOAAI
errYuyao Huang; Bingqing Song; Xuedong Zhou; Hui Chen; Haohao Wang; Lei Cheng
err分享
err收藏
Multi-view Instance Attention Fusion Network for classification
err2024-01-01
err3
errOAAI
errLi, Jinxing; Zhou, Chuhao; Ji, Xiaoqiang; Li, Mu; Lu, Guangming; Xu, Yong; Zhang, David
err分享
err收藏
err分享
err收藏
学者 查看更多内容