arXiv:2511.05102cs.CRcs.CV2025-11被引 1

提出新方法量化黑盒攻击风险,解决模型迁移攻击评估难题

Quantifying the Risk of Transferred Black Box Attacks

  • 用相似性匹配的代理模型优化对抗样本覆盖范围
  • 通过回归估计实现可操作的风险量化,避免穷举搜索
  • 适合安全合规团队用于评估模型抗攻击能力

神经网络在各类应用中广泛应用,包括安全相关产品。但其普及也加剧了对对抗攻击脆弱性的担忧。随着监管要求加强,组织必须可靠量化此类攻击风险,尤其是难以准确评估的迁移式对抗攻击。本文研究针对迁移式对抗攻击的鲁棒性测试复杂性,聚焦黑盒逃避攻击,因其实际意义强且在模型间转移性高。我们指出,完全覆盖高维输入空间在计算上不可行,因此全面对抗风险映射不切实际。为此,提出一种基于中心核对齐(CKA)相似性选择代理模型的目标化鲁棒性测试框架。通过选取与目标模型具有高/低CKA相似性的代理模型,优化对抗子空间的覆盖。利用基于回归的估计器进行风险评估,为组织提供现实且可操作的风险量化方案。

原文摘要 · Abstract (English)

Neural networks have become pervasive across various applications, including security-related products. However, their widespread adoption has heightened concerns regarding vulnerability to adversarial attacks. With emerging regulations and standards emphasizing security, organizations must reliably quantify risks associated with these attacks, particularly regarding transferred adversarial attacks, which remain challenging to evaluate accurately. This paper investigates the complexities involved in resilience testing against transferred adversarial attacks. Our analysis specifically addresses black-box evasion attacks, highlighting transfer-based attacks due to their practical significance and typically high transferability between neural network models. We underline the computational infeasibility of exhaustively exploring high-dimensional input spaces to achieve complete test coverage. As a result, comprehensive adversarial risk mapping is deemed impractical. To mitigate this limitation, we propose a targeted resilience testing framework that employs surrogate models strategically selected based on Centered Kernel Alignment (CKA) similarity. By leveraging surrogate models exhibiting both high and low CKA similarities relative to the target model, the proposed approach seeks to optimize coverage of adversarial subspaces. Risk estimation is conducted using regression-based estimators, providing organizations with realistic and actionable risk quantification.

对抗攻击风险评估黑盒攻击模型迁移

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。