arrow
Return

Query-efficient decision-based attack via sampling distribution reshaping

delete2022-09-01
delete13
PRE
AI
X
Xuxiang Sun
G
Gong Cheng *
L
Lei Pei
J
Junwei Han
DOI:10.1016/j.patcog.2022.108728delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
With a limited query budget and only the final decision of a target model, how to find adversarial examples with low-magnitude distortion has attracted great attention among researchers. Recent solutions to this issue made use of the estimated normal vector at a boundary data point to search for adversarial examples. However, since the sampling independence between two sampling epochs, they still suffer from a prohibitively high query budget, which will get worse when the dimensionality of the attacked samples get increased. To push for further development, in this paper, we pay attention to a query-efficient method to estimate the normal vector for decision-based attack in high-dimensional space. Specifically, we propose a simple yet effective normal vector estimation framework for high-dimension decision-based attack via Sampling Distribution Reshaping, dubbed SDR. Next, SDR is incorporated into general geometric attack framework. Briefly, SDR leverages all the historically sampled noise to build a guiding vector, which will be used to reshape the next sampling distribution. Besides, we also extend SDR to different l(p) norms for p = {2, infinity} col and deploy low-frequency constraint to enhance the performance of SDR. Compared to peer decision-based attacks, SDR can reach the competitive l(p) norms for p = {2, infinity}, according to extensive experimental evaluations against both defended and undefended classifiers. Since the simplicity and effectiveness of SDR, we think that reshaping the sampling distribution deserves further research in future works. (C) 2022 Elsevier Ltd. All rights reserved.
Keywords:
Adversarial examples
Decision-based attack
Image classification
Normal vector estimation
Distribution reshaping

Journal

Pattern Recognition cover
Pattern Recognition
IF:
7.6
Papers:
1.3W
Citations:
4.5W

Organization

N
Northwestern Polytechnical University
Scholars:
4.6W
Papers: 3.7W
Citations: 5.3W
Cited Papers

Cited Papers

Steganographic universal adversarial perturbations
err2020-07-01
err19
PREAI
errDin, Salah Ud; Akhtar, Naveed; Younis, Shahzad; Shafait, Faisal; Mansoor, Atif; Shafique, Muhammad
errShare
errSave
Visual Explanation for Deep Metric Learning
err2021-01-01
err17
errOAAI
errZhu, Sijie; Yang, Taojiannan; Chen, Chen
errShare
errSave
The Robustness of Deep Networks A geometrical perspective
err2017-11-01
err121
errOAAI
errFawzi, Alhussein; Moosavi-Dezfooli, Seyed-Mohsen; Frossard, Pascal
errShare
errSave
Adaptive iterative attack towards explainable adversarial robustness
err2020-09-01
err45
PREAI
errShi, Yucheng; Han, Yahong; Zhang, Quanxin; Kuang, Xiaohui
errShare
errSave
Universal adversarial perturbations against object detection
err2021-02-01
err30
PREAI
errLi, Debang; Zhang, Junge; Huang, Kaiqi
errShare
errSave
Coupled-dynamic learning for vision and language: Exploring Interaction between different tasks
err2021-05-01
err3
PREAI
errXu, Ning; Tian, Hongshuo; Wang, Yanhui; Nie, Weizhi; Song, Dan; Liu, An-An; Liu, Wu
errShare
errSave
errShare
errSave
researcher View more