A Black Box Attack Based on Visual Sensitivity

Cailong Li,Chunlong Fan,Jizhao Zhu,Zhenxin Zhang,Jianzhong Qiao
DOI: https://doi.org/10.1109/icus52573.2021.9641444
2021-01-01
Abstract:A bstract-Adversarial attack is an important research direction of neural network security, and the black box attack in the unknown model is an important application scenario against the attack. The adversarial samples generated by existing black-box attack algorithms often have drastic hue changes, are easy to perceive by human eyes, and the algorithm computational efficiency is generally low. Therefore, this paper proposes a multi-scale grid search for the image gray attack strategy, disturbs different intensity of different scales, and then makes the generated sample hue change more natural. Experiments show that the performance of the method is better than the baseline algorithm, and greatly improves the attack efficiency, increasing the neural network query number over 50% comparing with the fastest baseline algorithm.
What problem does this paper attempt to address?