paper-with-me

홈 › Papers

Generative Adversarial Networks for Black-Box API Attacks with Limited Training Data

2019-01-25 · Yi Shi, Yalin E. Sagduyu, Kemal Davaslioglu, Jason H. Li

As online systems based on machine learning are offered to public or paid subscribers via application programming interfaces (APIs), they become vulnerable to frequent exploits and attacks. This paper studies adversarial machine learning in the practical case when there are rate limitations on API calls. The adversary launches an exploratory (inference) attack by querying the API of an online machine learning system (in particular, a classifier) with input data samples, collecting returned labels to build up the training data, and training an adversarial classifier that is functionally equivalent and statistically close to the target classifier. The exploratory attack with limited training data is shown to fail to reliably infer the target classifier of a real text classifier API that is available online to the public. In return, a generative adversarial network (GAN) based on deep learning is built to generate synthetic training data from a limited number of real training data samples, thereby extending the training data and improving the performance of the inferred classifier. The exploratory attack provides the basis to launch the causative attack (that aims to poison the training process) and evasion attack (that aims to fool the classifier into making wrong decisions) by selecting training and test data samples, respectively, based on the confidence scores obtained from the inferred classifier. These stealth attacks with small footprint (using a small number of API calls) make adversarial machine learning practical under the realistic case with limited training data available to the adversary.

📄 PDF Abstract BibTeX arXiv:1901.09113

Code (0)

등록된 구현이 없습니다.

Tasks

BIG-bench Machine LearningGenerative Adversarial NetworkInference Attack

Similar Papers 제목 키워드 기반

A Generative Approach to Surrogate-based Black-box Attacks

2024-02-05 · Raha Moraffah, Huan Liu

Surrogate-based black-box attacks have exposed the heightened vulnerability of DNNs. These attacks are designed to craft adversarial examples for any samples with black-box target feedback for only a given set of samples…

Latent Danger Zone: Distilling Unified Attention for Cross-Architecture Black-box Attacks

2025-09-23 · Yang Li, Chenyu Wang, Tingrui Wang, Yongwei Wang 외 arxiv

Black-box adversarial attacks remain challenging due to limited access to model internals. Existing methods often depend on specific network architectures or require numerous queries, resulting in limited cross-architect…

SEBA: Sample-Efficient Black-Box Attacks on Visual Reinforcement Learning

2025-11-12 · Tairan Huang, Yulin Jin, Junxu Liu, Qingqing Ye 외 arxiv

Visual reinforcement learning has achieved remarkable progress in visual control and robotics, but its vulnerability to adversarial perturbations remains underexplored. Most existing black-box attacks focus on vector-bas…

Reinforcement LearningContinuous Control

Towards Efficient Data Free Black-Box Adversarial Attack

2022-01-01 · CVPR 2022 1 · Jie Zhang, Bo Li, Jianghe Xu, Shuang Wu 외

Classic black-box adversarial attacks can take advantage of transferable adversarial examples generated by a similar substitute model to successfully fool the target model. However, these substitute models need to be…

Adversarial Attack

Generating Adversarial Malware Examples for Black-Box Attacks Based on GAN

2017-02-20 · Weiwei Hu, Ying Tan

Machine learning has been used to detect new malware in recent years, while malware authors have strong motivation to attack such algorithms. Malware authors usually have no access to the detailed structures and paramete…

BIG-bench Machine LearningGenerative Adversarial NetworkMalware Detection