One for Many: an Instagram inspired black-box adversarial attack
It is well known that deep learning models are susceptible to adversarial attacks. To produce more robust and effective attacks, we propose a nested evolutionary algorithm able to produce multi-network (decision-based) black-box adversarial attacks based on Instagram inspired image filters. Due to the multi-network training, the system reaches a high transferability rate of attacks and, due to the composition of image filters, it is able to bypass standard detection mechanisms. Moreover, this kind of attack is semantically robust: our filter composition cannot be distinguished from any other filter composition used extensively every day to enhance images; this raises new security issues and challenges for real-world systems. Experimental results demonstrate that the method is also effective against ensemble-adversarially trained models and it has a low cost in terms of queries to the victim model.
Code (0)
등록된 구현이 없습니다.
Tasks
Adversarial AttackSimilar Papers 제목 키워드 기반
Log-normal Mutations and their Use in Detecting Surreptitious Fake Images
In many cases, adversarial attacks are based on specialized algorithms specifically dedicated to attacking automatic image classifiers. These algorithms perform well, thanks to an excellent ad hoc distribution of initial…
Meta Gradient Adversarial Attack
In recent years, research on adversarial attacks has become a hot spot. Although current literature on the transfer-based adversarial attack has achieved promising results for improving the transferability to unseen blac…
Adversarial AttackMeta-LearningLearn2Weight: Weights Transfer Defense against Similar-domain Adversarial Attacks
Recent work in black-box adversarial attacks for NLP systems has attracted attention. Prior black-box attacks assume that attackers can observe output labels from target models based on selected inputs. In this work, ins…
Adversarial AttackDomain AdaptationMulti-Domain Sentiment ClassificationSentiment Analysis+1Learn2Weight: Parameter Adaptation against Similar-domain Adversarial Attacks
Recent work in black-box adversarial attacks for NLP systems has attracted much attention. Prior black-box attacks assume that attackers can observe output labels from target models based on selected inputs. In this work…
Adversarial AttackDomain AdaptationMeta-LearningMulti-Domain Sentiment Classification+2SMART: Skeletal Motion Action Recognition aTtack
Adversarial attack has inspired great interest in computer vision, by showing that classification-based solutions are prone to imperceptible attack in many tasks. In this paper, we propose a method, SMART, to attack acti…
Action RecognitionAdversarial AttackTime SeriesTime Series Analysis