paper-with-me

홈 › Papers

Beyond ImageNet Attack: Towards Crafting Adversarial Examples for Black-box Domains

2022-01-27 · ICLR 2022 4 · Qilong Zhang, Xiaodan Li, Yuefeng Chen, Jingkuan Song, Lianli Gao, Yuan He, Hui Xue

Adversarial examples have posed a severe threat to deep neural networks due to their transferable nature. Currently, various works have paid great efforts to enhance the cross-model transferability, which mostly assume the substitute model is trained in the same domain as the target model. However, in reality, the relevant information of the deployed model is unlikely to leak. Hence, it is vital to build a more practical black-box threat model to overcome this limitation and evaluate the vulnerability of deployed models. In this paper, with only the knowledge of the ImageNet domain, we propose a Beyond ImageNet Attack (BIA) to investigate the transferability towards black-box domains (unknown classification tasks). Specifically, we leverage a generative model to learn the adversarial function for disrupting low-level features of input images. Based on this framework, we further propose two variants to narrow the gap between the source and target domains from the data and model perspectives, respectively. Extensive experiments on coarse-grained and fine-grained domains demonstrate the effectiveness of our proposed methods. Notably, our methods outperform state-of-the-art approaches by up to 7.71\% (towards coarse-grained domains) and 25.91\% (towards fine-grained domains) on average. Our code is available at \url{https://github.com/qilong-zhang/Beyond-ImageNet-Attack}.

📄 PDF Abstract BibTeX arXiv:2201.11528

Code (2)

Alibaba-AAIG/Beyond-ImageNet-Attack 공식 구현 pytorch
qilong-zhang/beyond-imagenet-attack 공식 구현 pytorch

Similar Papers 제목 키워드 기반

EAD: Elastic-Net Attacks to Deep Neural Networks via Adversarial Examples

2017-09-13 · Pin-Yu Chen, Yash Sharma, huan zhang, Jin-Feng Yi 외

Recent studies have highlighted the vulnerability of deep neural networks (DNNs) to adversarial examples - a visually indistinguishable adversarial image can easily be crafted to cause a well-trained model to misclassify…

Adversarial AttackAdversarial Robustness

GSBA$^K$: $top$-$K$ Geometric Score-based Black-box Attack

2025-03-17 · Md Farhamdur Reza, Richeng Jin, Tianfu Wu, Huaiyu Dai

Existing score-based adversarial attacks mainly focus on crafting $top$-1 adversarial examples against classifiers with single-label classification. Their attack success rate and query efficiency are often less than sati…

Multi-Label Learning

Evading classifiers in discrete domains with provable optimality guarantees

2018-10-25 · Bogdan Kulynych, Jamie Hayes, Nikita Samarin, Carmela Troncoso

Machine-learning models for security-critical applications such as bot, malware, or spam detection, operate in constrained discrete domains. These applications would benefit from having provable guarantees against advers…

Adversarial RobustnessSpam detectionTwitter Bot Detectionvalid

Adversarial Attacks and Detection on Reinforcement Learning-Based Interactive Recommender Systems

2020-06-14 · Yuanjiang Cao, Xiaocong Chen, Lina Yao, Xianzhi Wang 외

Adversarial attacks pose significant challenges for detecting adversarial attacks at an early stage. We propose attack-agnostic detection on reinforcement learning-based interactive recommendation systems. We first craft…

Interactive RecommendationRecommendation Systemsreinforcement-learningReinforcement Learning (RL)

Backpropagating Linearly Improves Transferability of Adversarial Examples

2020-12-07 · NeurIPS 2020 12 · Yiwen Guo, Qizhang Li, Hao Chen

The vulnerability of deep neural networks (DNNs) to adversarial examples has drawn great attention from the community. In this paper, we study the transferability of such examples, which lays the foundation of many black…