Nonlinear Gradient Estimation for Query Efficient Blackbox Attack

Huichen Li,Linyi Li,Xiaojun Xu,Xiaolu Zhang,Shuang Yang,Bo Li
2020-01-01
Abstract:Gradient projection and gradient estimation have been studied as two distinct topics. We aim to bridge the gap between the two by investigating how gradient can be effectively estimated from a projected low-dimensional space. We provide lower and upper bounds for gradient estimation under both linear and non-linear projections. Moreover, we analyze the query complexity for the projection-based gradient estimation. Built upon our theoretic analysis, we propose a novel query-efficient Nonlinear Gradient Projection-based B oundary-based Black-box A ttack ( NonLinear-BA ). We show that the boundary blackbox attack with projection-based gradient estimation is able to achieve a much smaller magnitude of perturbation with the same number of queries and a 100% attack success rate. We also evaluate NonLinear-BA against commercial online API MEGVII Face++ and demonstrate high attack performance.
What problem does this paper attempt to address?