arrow
Return

Explore Adversarial Attack via Black Box Variational Inference

delete2022-01-01
delete1
PRE
AI
C
Chenglong Zhao
B
Bingbing Ni *
S
Shibin Mei
DOI:10.1109/LSP.2022.3208417delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
From the perspective of probability, we propose a new method for black-box adversarial attack via black-box variational inference (BBVI), where the knowledge of victim model is unavailable. Instead of obtaining a single point, the proposed method focuses on approximating the probability distribution of adversarial examples. Thus, infinite adversarial examples can be drawn from the inferred distribution. Although the Monte Carlo estimator in BBVI is unbiased, its variance brings unstable gradient estimation, which leads to poor attack performance and low query efficiency. To reduce variance, we improve the BBVI with importance sampling which guided by a surrogate model to obtain a better estimator of gradient, which enhances both success rate and query efficiency. Extensive experiments on ImageNet dataset well demonstrate the outperformance of the proposed method compared with prior arts.
Keywords:
Monte Carlo methods
Computational modeling
Probability distribution
Gaussian distribution
Bayes methods
Art
Stochastic processes
Adversarial attack
importance sampling
Bayesian inference

Journal

IEEE Signal Processing Magazine cover
IEEE Signal Processing Magazine
IF:
9.6
Papers:
1.1W
Citations:
1.7W

Organization

S
shanghai jiao tong university
Scholars:
15.6W
Papers: 11.6W
Citations: 159