QRPatch: A Deceptive Texture-Based Black-Box Adversarial Attacks with Genetic Algorithm.

Chao Li,Wen Yao,Handing Wang,Tingsong Jiang,Donghua Wang,Jialiang Sun
DOI: https://doi.org/10.1109/CEC60901.2024.10611945
2024-01-01
Abstract:Patch-based attacks are a major black-box attack paradigm, where there is no limit to the intensity of the perturbation. The existing patch-based attack methods focus on obtaining the optimal position, shape, and pixel values against adversarial patches, however, the generated patch looks conspicuous and makes it easy to attract people's attention. Quick response(QR) code has been widely used in various fields, such as image copyright protection, stored image information. Further, it does not get noticed when a QR code is attached to the image. Therefore, we propose a deceptive texture-based black-box adversarial attack method to address the above problem. Specifically, we use the QR code pattern as the basis of the adversarial patches. Then, we model the adversarial attack as a discrete optimization problem, where the optimization variables are designed as the center coordinates of the patch pasting locations and the pixel values. Further, an upsampling technique is introduced to reduce the dimension of the optimization variables. Finally, genetic algorithm is employed as the optimizer to obtain the optimal parameter of the patch. In order to verify the effectiveness of the proposed method, we compare a number of the state-of-the-art patch-based attack methods on the ImageNet dataset, and the experimental results show that the proposed method can effectively generate deceptive adversarial examples in both digital and physical space and obtain the best attack performance, especially for the defense models.
What problem does this paper attempt to address?