Hybrid Batch Attacks: Finding Black-box Adversarial Examples with Limited Queries

Hybrid Batch Attacks: Finding Black-box Adversarial Examples with Limited Queries
复制标题

DOI:
--
复制
发表时间:
2019-08
期刊:
ArXiv
影响因子:
--
通讯作者:
Fnu Suya;Jianfeng Chi;David Evans;Yuan Tian
Fnu Suya;Jianfeng Chi;David Evans;Yuan Tian
中科院分区:
其他
文献类型:
--
作者:
Fnu Suya;Jianfeng Chi;David Evans;Yuan Tian

文献摘要

被引文献

相似文献

我们在黑盒设置中研究对抗性示例,其中攻击者只有对目标模型的API访问权限,并且每个查询都是昂贵的。先前针对黑盒对抗示例的工作遵循两种主要策略之一:(1)转移攻击使用对局部模型的白盒攻击来寻找转移到目标模型的候选对抗示例;(2)基于优化的攻击使用对目标模型的查询并应用优化技术来搜索对抗示例。我们提出了结合这两种策略的混合攻击,使用来自局部模型的候选对抗性示例作为基于优化的攻击的起点,并使用基于优化的攻击中学习的标签来调整局部模型以寻找转移候选。我们在MNIST, CIFAR10和ImageNet数据集上进行了实证证明,我们的混合攻击策略降低了成本并提高了成功率。我们还引入了种子优先级策略,使攻击者能够将资源集中在最有希望的种子上。将混合攻击与我们的种子优先级策略相结合,可以实现批处理攻击,只需少量查询就可以可靠地找到对抗性示例。
We study adversarial examples in a black-box setting where the adversary only has API access to the target model and each query is expensive. Prior work on black-box adversarial examples follows one of two main strategies: (1) transfer attacks use white-box attacks on local models to find candidate adversarial examples that transfer to the target model, and (2) optimization-based attacks use queries to the target model and apply optimization techniques to search for adversarial examples. We propose hybrid attacks that combine both strategies, using candidate adversarial examples from local models as starting points for optimization-based attacks and using labels learned in optimization-based attacks to tune local models for finding transfer candidates. We empirically demonstrate on the MNIST, CIFAR10, and ImageNet datasets that our hybrid attack strategy reduces cost and improves success rates. We also introduce a seed prioritization strategy which enables attackers to focus their resources on the most promising seeds. Combining hybrid attacks with our seed prioritization strategy enables batch attacks that can reliably find adversarial examples with only a handful of queries.