资源论文BLACK -B OX ADVERSARIAL ATTACK WITH TRANS -FERABLE MODEL -BASED EMBEDDING

BLACK -B OX ADVERSARIAL ATTACK WITH TRANS -FERABLE MODEL -BASED EMBEDDING

2020-01-02 | |  53 |   36 |   0

Abstract

We present a new method for black-box adversarial attack. Unlike previous methods that combined transfer-based and scored-based methods by using the gradient or initialization of a surrogate white-box model, this new method tries to learn a low-dimensional embedding using a pretrained model, and then performs efficient search within the embedding space to attack an unknown target network. The method produces adversarial perturbations with high level semantic patterns that are easily transferable. We show that this approach can greatly improve the query efficiency of black-box adversarial attack across different target network architectures. We evaluate our approach on MNIST, ImageNet and Google Cloud Vision API, resulting in a significant reduction on the number of queries. We also attack adversarially defended networks on CIFAR10 and ImageNet, where our method not only reduces the number of queries, but also improves the attack success rate.

上一篇:ROBUST TRAINING WITH ENSEMBLE CONSENSUS

下一篇:PRINCIPLED WEIGHT INITIALIZATION FOR HYPERNETW ORKS

用户评价
全部评价

热门资源

  • Stratified Strate...

    In this paper we introduce Stratified Strategy ...

  • The Variational S...

    Unlike traditional images which do not offer in...

  • Learning to learn...

    The move from hand-designed features to learned...

  • A Mathematical Mo...

    Direct democracy, where each voter casts one vo...

  • Learning to Predi...

    Much of model-based reinforcement learning invo...