利用目标图像边缘信息,高效实现低查询黑盒攻击
Accelerating Targeted Hard-Label Adversarial Attacks in Low-Query Black-Box Settings
- 基于目标图像边缘信息设计扰动,提升攻击精度
- 低查询场景下减少近70%请求次数,性能超越现有方法
- 适合资源受限的现实黑盒攻击场景
深度神经网络在图像分类任务中仍易受对抗样本影响——微小且难以察觉的扰动可导致分类错误。在仅能访问最终预测结果的黑盒设置下,将输入误导至特定目标类别的定向攻击尤为困难,因目标类别决策区域狭窄。现有最优方法通常依赖源图像与目标图像间决策边界的几何特性,而未充分使用图像本身的信息。本文提出目标边缘感知攻击(TEA),通过利用目标图像的边缘特征进行精准扰动,在保持与源图像相近的同时实现目标分类。该方法在多种模型上均显著优于当前最优方法,尤其在低查询场景下,平均减少近70%查询次数,更适用于真实世界中查询受限的黑盒环境。此外,其生成的高质量对抗样本可作为经典几何基攻击的有效初始值。
原文摘要 · Abstract (English)
Deep neural networks for image classification remain vulnerable to adversarial examples -- small, imperceptible perturbations that induce misclassifications. In black-box settings, where only the final prediction is accessible, crafting targeted attacks that aim to misclassify into a specific target class is particularly challenging due to narrow decision regions. Current state-of-the-art methods often exploit the geometric properties of the decision boundary separating a source image and a target image rather than incorporating information from the images themselves. In contrast, we propose Targeted Edge-informed Attack (TEA), a novel attack that utilizes edge information from the target image to carefully perturb it, thereby producing an adversarial image that is closer to the source image while still achieving the desired target classification. Our approach consistently outperforms current state-of-the-art methods across different models in low query settings (nearly 70% fewer queries are used), a scenario especially relevant in real-world applications with limited queries and black-box access. Furthermore, by efficiently generating a suitable adversarial example, TEA provides an improved target initialization for established geometry-based attacks.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。