arrow
返回

Query-efficient label-only attacks against black-box machine learning models

delete2020-03-01
delete9
PRE
AI
Y
Yizhi Ren
Q
Qi Zhou
Z
Zhen Wang *
T
Ting Wu
G
Guohua Wu
K
Kim‐Kwang Raymond Choo
DOI:10.1016/j.cose.2019.101698delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Recent studies have shown that machine learning algorithms are susceptible to imperceptible perturbations. These studies focus on the laboratory environment, where the attacker has knowledge about internal information of the victim model or feedbacks such as class probabilities. There is still a gap between theory and physical world, the risk of adversarial attacks under the more extreme and realistic condition needs to be figured out. Here we propose a knowledge restricted black-box attack model where the attacker can only get the final predict label. In the meantime, we model the attacker as a resource-restricted one, such as query-limited. The limitations of knowledge level and resources make previous work unable to be directly applied. For this problem, the current state-of-the-art method is boundary attack, however it requires large a number of queries. In this paper, we make several contributions to investigate the vulnerability of machine learning models in more realistic scenarios. First, we reconstruct the optimization problem, measure the quality of the sample points by L2 distance. Second, we provide a more effective algorithm, using cutting plane method and local optimization. Third, we propose two effective dynamic defense strategy, which is easy to implement. At last, we conduct an experimental evaluation on MNIST, Fashion-MNIST and malware detection datasets. The results show that (1) compared with state-of-the-art method, our cutting plane method reduces the number of queries while ensuring the attack efficiency; (2) Dynamic defense strategy is effective against label-only adversarial attacks, the rate of attack success dropped from nearly 100% to 23%, with a considerable classification accuracy; (3) Improved defense strategy guarantees the effectiveness of defense and improves the stability of the whole model. (C) 2019 Elsevier Ltd. All rights reserved.
Keyword:
Adversarial sample
Machine learning
Image recognition
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

C
Computers and Security
IF:
5.4
论文数:
4.6K
被引数:
1.4W

机构

H
Hangzhou Dianzi University
学者数:
1.3W
论文数: 9.6K
被引数: 7.5K
U
university of texas system
学者数:
18.5W
论文数: 15.6W
被引数: 210
引用论文

引用论文

暂无论文信息