用共识优化提升黑盒攻击效果,比进化策略更优。
Consensus-based optimization for closed-box adversarial attacks and a connection to evolution strategies
- 基于共识机制的无梯度优化,不依赖模型梯度。
- 实验显示在特定场景下优于自然进化策略。
- 连接了共识跳跃与进化策略,揭示其优化本质。
共识基优化(CBO)是一种高效的无梯度优化方法,具有良好的数学性质,如非凸损失函数下的均场收敛性。本文研究CBO在黑盒对抗攻击中的应用,即在无法获取模型梯度的情况下,生成难以察觉的输入扰动以欺骗分类器。我们的贡献在于建立了Riedl等人提出的“共识跳跃”与常用于对抗攻击的自然进化策略(NES)之间的联系,并严格将两者与基于梯度的优化方法关联起来。此外,我们进行了全面的实验分析,结果表明尽管二者概念相似,但在某些场景下CBO仍能超越NES及其他进化策略。
原文摘要 · Abstract (English)
Consensus-based optimization (CBO) has established itself as an efficient gradient-free optimization scheme, with attractive mathematical properties, such as mean-field convergence results for non-convex loss functions. In this work, we study CBO in the context of closed-box adversarial attacks, which are imperceptible input perturbations that aim to fool a classifier, without accessing its gradient. Our contribution is to establish a connection between the so-called consensus hopping as introduced by Riedl et al. and natural evolution strategies (NES) commonly applied in the context of adversarial attacks and to rigorously relate both methods to gradient-based optimization schemes. Beyond that, we provide a comprehensive experimental study that shows that despite the conceptual similarities, CBO can outperform NES and other evolutionary strategies in certain scenarios.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。