【论文阅读】Learning Black-Box Attackers with Transferable Priors and Query Feedback(2020)

摘要

This paper addresses(解决) the challenging black-box adversarial attack problem(黑盒对抗攻击问题), where only classification confidence(分类置信度) of a victim model(受害者模型) is available. Inspired by consistency(一致性) of visual saliency(视觉显著性) between different vision models(视觉模型), a surrogate model(代理模型) is expected to improve the attack performance(攻击性能) via transferability(可转移性). By combining(结合) transferability-based(基于可转移性) and query-based(基于查询) black-box attack, we propose a surprisingly simple baseline approach(基线方法) (named SimBA++) using the surrogate model(代理模型), which significantly outperforms(明显优于) several state-of-the-art(最先进的) methods. Moreover(此外), to efficiently utilize(有效利用) the query feedbac(查询反馈), we update the surrogate model(代理模型) in a novel learning scheme(新的学习方案), named High-Order Gradient Approximation (HOGA 高阶梯度近似). By constructing(构造) a high-order gradient computation graph(高阶梯度计算图), we update the surrogate model to approximate(逼近) the victim model in both forward and backward pass(正向和反向传递). The SimBA++ and HOGA result in Learnable Black-Box Attack(可学习的黑盒攻击) (LeBA), which surpasses(超过) previous state of the art by considerable margins: the proposed LeBA significantly reduces queries(减少了查询), while keeping higher attack success rates(攻击成功率) close to(接近) 100% in extensive(广泛的) Ima-geNet experiments, including attacking vision benchmarks and defensive models(攻击视觉基准和防御模型).

算法

在这里插入图片描述

论文链接

Learning black-box attackers with transferable priors and query feedback

笔记

在模型窃取攻击中,攻击者通过对受害者模型进行查询,并利用查询结果反向构建具有相似功能的替代模型。然后,攻击者可以利用替代模型发起进一步的对抗攻击。

  • 6
    点赞
  • 8
    收藏
    觉得还不错? 一键收藏
  • 打赏
    打赏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包

打赏作者

Bosenya12

你的鼓励将是我创作的最大动力

¥1 ¥2 ¥4 ¥6 ¥10 ¥20
扫码支付:¥1
获取中
扫码支付

您的余额不足,请更换扫码支付或充值

打赏作者

实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值