CGBA: Curvature-aware Geometric Black-box Attack

CGBA: Curvature-aware Geometric Black-box Attack
复制标题

DOI:
10.1109/iccv51070.2023.00018
复制
发表时间:
2023-08
期刊:
2023 IEEE/CVF International Conference on Computer Vision (ICCV)
影响因子:
--
通讯作者:
Md. Farhamdur Reza;A. Rahmati;Tianfu Wu;H. Dai
Md. Farhamdur Reza;A. Rahmati;Tianfu Wu;H. Dai
中科院分区:
其他
文献类型:
--
作者:
Md. Farhamdur Reza;A. Rahmati;Tianfu Wu;H. Dai

文献摘要

相似文献

基于决策的黑盒攻击通常需要大量查询来创建对抗性示例。此外,基于在估计的法向量方向上查询边界点的基于决策的攻击通常遭受低效率和收敛问题。在本文中,我们提出了一种新的查询效率的曲率感知几何决策为基础的黑盒攻击(CGBA),进行边界搜索沿着一个半圆形的路径上的限制二维平面,以确保找到一个边界点成功地不考虑边界曲率。虽然所提出的CGBA攻击可以有效地用于任意决策边界,但它在利用低曲率来制作高质量的对抗性示例方面特别有效,这在非目标攻击下的常用分类器中被广泛观察和实验验证。相比之下,决策边界往往表现出更高的曲率下有针对性的攻击。因此,我们开发了一个新的查询效率的变种,CGBA-H,这是适应有针对性的攻击。此外,我们进一步设计了一个算法,以获得一个更好的初始边界点在一些额外的查询为代价,这大大提高了有针对性的攻击的性能。进行了大量的实验,以评估我们提出的方法在ImageNet和CIFAR 10数据集上对一些知名分类器的性能,证明CGBA和CGBA-H分别优于最先进的非目标攻击和目标攻击。源代码可在https://github.com/Farhamdur/CGBA上获得。
Decision-based black-box attacks often necessitate a large number of queries to craft an adversarial example. Moreover, decision-based attacks based on querying boundary points in the estimated normal vector direction often suffer from inefficiency and convergence issues. In this paper, we propose a novel query-efficient curvature-aware geometric decision-based black-box attack (CGBA) that conducts boundary search along a semicircular path on a restricted 2D plane to ensure finding a boundary point successfully irrespective of the boundary curvature. While the proposed CGBA attack can work effectively for an arbitrary decision boundary, it is particularly efficient in exploiting the low curvature to craft high-quality adversarial examples, which is widely seen and experimentally verified in commonly used classifiers under non-targeted attacks. In contrast, the decision boundaries often exhibit higher curvature under targeted attacks. Thus, we develop a new query-efficient variant, CGBA-H, that is adapted for the targeted attack. In addition, we further design an algorithm to obtain a better initial boundary point at the expense of some extra queries, which considerably enhances the performance of the targeted attack. Extensive experiments are conducted to evaluate the performance of our proposed methods against some well-known classifiers on the ImageNet and CIFAR10 datasets, demonstrating the superiority of CGBA and CGBA-H over state-of-the-art non-targeted and targeted attacks, respectively. The source code is available at https://github.com/Farhamdur/CGBA.