Simple Black-box Adversarial Attacks

Simple Black-box Adversarial Attacks
复制标题

DOI:
--
复制
发表时间:
2019-05
期刊:
ArXiv
影响因子:
--
通讯作者:
Chuan Guo;J. Gardner;Yurong You;A. Wilson;Kilian Q. Weinberger
Chuan Guo;J. Gardner;Yurong You;A. Wilson;Kilian Q. Weinberger
中科院分区:
其他
文献类型:
--
作者:
Chuan Guo;J. Gardner;Yurong You;A. Wilson;Kilian Q. Weinberger

文献摘要

被引文献

相似文献

我们提出了一个有趣的简单的方法,用于在黑盒设置中构建对抗图像。在白盒场景中,构建黑盒对抗图像对查询预算有额外的约束,有效的攻击仍然是一个悬而未决的问题。只有连续值置信分数的温和假设,我们的高查询效率算法利用以下简单的迭代原理:我们从预定义的正交基随机采样一个向量,并将其添加或减去目标图像。尽管它很简单,但所提出的方法可以用于无目标和有目标的攻击,从而在这两种情况下都实现了前所未有的查询效率。我们证明了我们的算法在几个真实的世界设置,包括谷歌云视觉API的功效和效率。我们认为,我们提出的算法应该作为未来黑盒攻击的强大基线,特别是因为它非常快,其实现需要不到20行PyTorch代码。
We propose an intriguingly simple method for the construction of adversarial images in the black-box setting. In constrast to the white-box scenario, constructing black-box adversarial images has the additional constraint on query budget, and efficient attacks remain an open problem to date. With only the mild assumption of continuous-valued confidence scores, our highly query-efficient algorithm utilizes the following simple iterative principle: we randomly sample a vector from a predefined orthonormal basis and either add or subtract it to the target image. Despite its simplicity, the proposed method can be used for both untargeted and targeted attacks -- resulting in previously unprecedented query efficiency in both settings. We demonstrate the efficacy and efficiency of our algorithm on several real world settings including the Google Cloud Vision API. We argue that our proposed algorithm should serve as a strong baseline for future black-box attacks, in particular because it is extremely fast and its implementation requires less than 20 lines of PyTorch code.