Enhancing Black-Box Attacks With Self-Supervised Features and Luminance-Aware Visual Model

Siying Xue,Wei Wu
DOI: https://doi.org/10.1109/access.2023.3314669
IF: 3.9
2023-09-22
IEEE Access
Abstract:The practical utility of black-box adversarial attacks in deep learning security has gained significant attention. However, current black-box attacks face challenges related to overfitting, leading to limited transferability of adversarial samples. This limitation arises from excessive iterations, limited input diversity during sample generation, and indiscriminate perturbation addition. To address these issues, this paper proposes a novel approach. Adversarial perturbations are generated using a self-supervised model with strong generalization capabilities, resulting in enhanced transferability of adversarial samples. Furthermore, dynamic perturbation range maps are generated based on nonlinear characteristics of human eye luminance perception. A random gamma transform is also introduced to increase input diversity and mitigate overfitting. Extensive experiments on ImageNet datasets demonstrate the significant improvement in adversarial sample transferability achieved by our method. Moreover, our approach can be effectively combined with other techniques, achieving an average success rate of 91.70% against normal models and 74.90% against defensive models when using solely normally trained models.
computer science, information systems,telecommunications,engineering, electrical & electronic
What problem does this paper attempt to address?