CRAICVLGOct 21, 2020

Learning Black-Box Attackers with Transferable Priors and Query Feedback

arXiv:2010.11742v192 citationsHas Code
Originality Highly original
AI Analysis

This work addresses the challenge of efficiently attacking machine learning models with limited access, offering a method that improves performance for security testing and adversarial robustness evaluation.

The paper tackles the black-box adversarial attack problem by proposing LeBA, which combines transferability from a surrogate model with query feedback to significantly reduce the number of queries needed while maintaining near 100% attack success rates on ImageNet benchmarks and defensive models.

This paper addresses the challenging black-box adversarial attack problem, where only classification confidence of a victim model is available. Inspired by consistency of visual saliency between different vision models, a surrogate model is expected to improve the attack performance via transferability. By combining transferability-based and query-based black-box attack, we propose a surprisingly simple baseline approach (named SimBA++) using the surrogate model, which significantly outperforms several state-of-the-art methods. Moreover, to efficiently utilize the query feedback, we update the surrogate model in a novel learning scheme, named High-Order Gradient Approximation (HOGA). By constructing a high-order gradient computation graph, we update the surrogate model to approximate the victim model in both forward and backward pass. The SimBA++ and HOGA result in Learnable Black-Box Attack (LeBA), which surpasses previous state of the art by considerable margins: the proposed LeBA significantly reduces queries, while keeping higher attack success rates close to 100% in extensive ImageNet experiments, including attacking vision benchmarks and defensive models. Code is open source at https://github.com/TrustworthyDL/LeBA.

Code Implementations1 repo
Foundations

The foundational work for this paper's niche, ranked by how specifically the neighbourhood builds on it — not by global fame.

Your Notes