Boosting Query Efficiency of Meta Attack with Dynamic Fine-Tuning.

Da Lin,Yuan-Gen Wang,Weixuan Tang,Xiangui Kang
DOI: https://doi.org/10.1109/lsp.2022.3229558
2022-01-01
IEEE Signal Processing Letters
Abstract:In black-box attack, excessive queries to target model may cause suspicion and expose attacker's identity. Equipped with advanced meta learning technique, Meta Attack simulates the target model with a surrogate model, significantly reducing the queries. However, it queries for ZOO-gradients to correct the estimated meta-gradients with a fixed frequency, thereby still leading to massive unnecessary queries. To overcome this limitation, this letter takes the dynamic changes of the accuracy of the estimated gradients as a starting point, and develops a Dynamic Meta Attack (DMA). At the beginning of each fine-tuning round, DMA computes the distance between the above two types of gradients. Such distance metric can reflect the accuracy of the meta-gradients, and guide the dynamic adjustment of query frequency for the ZOO-gradients. Moreover, the working flow of the dynamic fine-tuning process can be controlled by a set of parameters, which are of physical significance and easy to be tuned. By this means, DMA merely launches queries at critical moments, greatly saving query resource. Experiments conducted on MNIST and CIFAR10 show that the proposed DMA requires far fewer queries than existing methods while maintaining a satisfying attack success rate and distortion.
What problem does this paper attempt to address?