用强化学习改进三角攻击,查询次数减半仍更有效
Theoretical Corrections and the Leveraging of Reinforcement Learning to Enhance Triangle Attack
- 引入强化学习优化攻击路径选择
- 在ImageNet和CIFAR-10上查询量减半,准确率相当或更高
- 适合研究黑箱攻击与防御的学者参考
对抗样本是机器学习模型在敏感领域应用中的严重问题。在生成对抗样本方面,基于决策的黑盒攻击是最实用的技术之一,仅需访问模型查询接口即可。近期最先进的一种基于决策的黑盒攻击是三角攻击(Triangle Attack, TA)。本文对TA进行高层描述并揭示其潜在理论局限。为此,我们提出一种新的基于决策的黑盒攻击——基于强化学习的三角攻击(TARL)。该方法通过引入强化学习克服了TA的限制,使攻击在ImageNet和CIFAR-10上的主流分类器与防御机制下,以一半的查询次数实现与TA相当甚至更优的攻击准确率。
原文摘要 · Abstract (English)
Adversarial examples represent a serious issue for the application of machine learning models in many sensitive domains. For generating adversarial examples, decision based black-box attacks are one of the most practical techniques as they only require query access to the model. One of the most recently proposed state-of-the-art decision based black-box attacks is Triangle Attack (TA). In this paper, we offer a high-level description of TA and explain potential theoretical limitations. We then propose a new decision based black-box attack, Triangle Attack with Reinforcement Learning (TARL). Our new attack addresses the limits of TA by leveraging reinforcement learning. This creates an attack that can achieve similar, if not better, attack accuracy than TA with half as many queries on state-of-the-art classifiers and defenses across ImageNet and CIFAR-10.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。