Query Efficient Black-Box Adversarial Attack on Deep Neural Networks

Yang Bai,Yisen Wang,Yuyuan Zeng,Yong Jiang,Shu-Tao Xia
DOI: https://doi.org/10.1016/j.patcog.2022.109037
IF: 8
2023-01-01
Pattern Recognition
Abstract:•We explore the flexible versions of NP-Attack, when combined with the surrogate models. Our method could show a better query efficiency, demonstrating that NP-Attack outperforms with or without surrogate models.•We add some tiling tricks on NP-Attack to improve query efficiency. Moreover, we also design some ablation study experiments on tiling parameters.•We also evaluate NP-Attack on adversarial defense models to further discuss the capability of our method. Extensive experiments on benchmark demonstrate that our NP-Attack still outperforms existing evolution strategy methods in these black-box attack tasks.
What problem does this paper attempt to address?