arXiv:2503.12827cs.CV2025-03被引 5

提出新型无代理黑盒攻击,高效生成多标签分类器的top-K对抗样本。

GSBA$^K$: $top$-$K$ Geometric Score-based Black-box Attack

  • 基于梯度估计与决策边界几何特性,构建top-K攻击新方法。
  • 在ImageNet和PASCAL VOC上实现高成功率与低查询次数,优于现有方法。
  • 适用于单标签与多标签分类器,尤其适合小扰动场景下的安全评估。

现有基于得分的对抗攻击主要针对单标签分类器的top-1对抗样本,其成功率与查询效率在小扰动条件下常不理想,且对多标签学习模型的脆弱性研究不足。本文提出一种无需替代模型的几何得分黑盒攻击方法GSBA$^K$,可针对未指定与指定目标的攻击,在top-K设置下改变目标分类器的top-K预测结果。通过新颖的梯度方法确定初始攻击点,迭代过程中采用高效的梯度估计技术,充分挖掘决策边界的几何特性。此外,该方法可扩展至支持top-K多标签学习的分类器。在ImageNet与PASCAL VOC数据集上的大量实验验证了其在生成top-K对抗样本方面的有效性。

原文摘要 · Abstract (English)

Existing score-based adversarial attacks mainly focus on crafting $top$-1 adversarial examples against classifiers with single-label classification. Their attack success rate and query efficiency are often less than satisfactory, particularly under small perturbation requirements; moreover, the vulnerability of classifiers with multi-label learning is yet to be studied. In this paper, we propose a comprehensive surrogate free score-based attack, named \b geometric \b score-based \b black-box \b attack (GSBA$^K$), to craft adversarial examples in an aggressive $top$-$K$ setting for both untargeted and targeted attacks, where the goal is to change the $top$-$K$ predictions of the target classifier. We introduce novel gradient-based methods to find a good initial boundary point to attack. Our iterative method employs novel gradient estimation techniques, particularly effective in $top$-$K$ setting, on the decision boundary to effectively exploit the geometry of the decision boundary. Additionally, GSBA$^K$ can be used to attack against classifiers with $top$-$K$ multi-label learning. Extensive experimental results on ImageNet and PASCAL VOC datasets validate the effectiveness of GSBA$^K$ in crafting $top$-$K$ adversarial examples.

对抗攻击黑盒攻击top-K多标签

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。