跳到主要导航 跳到搜索 跳到主要内容

GCSA: A New Adversarial Example-Generating Scheme Toward Black-Box Adversarial Attacks

  • Xinxin Fan*
  • , Mengfan Li
  • , Jia Zhou
  • , Quanliang Jing
  • , Chi Lin
  • , Yunfeng Lu
  • , Jingping Bi
  • *此作品的通讯作者
  • CAS - Institute of Computing Technology
  • Bank of Communications
  • Dalian University of Technology

科研成果: 期刊稿件文章同行评审

摘要

This paper focuses on the transferability problem of adversarial examples towards black-box attack scenarios wherein model information such as the neural network structure is unavailable. To tackle this predicament, we propose a new adversarial example-generating scheme through bridging a data-modal conversion regime to spawn transferable adversarial examples without referring to the substitute model. Three contributions are mainly involved: i) we figure out an integrated framework to produce transferable adversarial examples through resorting to three components, i.e., image-to-graph conversion, perturbation on converted graph and graph-to-image inversion; ii) upon the conversion from image to graph, we pinpoint critical graph characteristics to implement perturbation using gradient-oriented and optimization-oriented adversarial attacks, then, invert the perturbation on graph into the pixel disturbance correspondingly; iii) multi-facet experiments verify the reasonability and effectiveness with the comparison to three baseline methods. Our work has two novelties: first, without referring to the substitute model, our proposed scheme does not need to acquire any information about the victim model in advance; second, we explore the possibility that inferring the adversarial features of image data through drawing support from network/graph science. In addition, we present three key issues worth deeper discussion, along with these open issues, our work deserves more studies in future.

源语言英语
页(从-至)2038-2048
页数11
期刊IEEE Transactions on Consumer Electronics
70
1
DOI
出版状态已出版 - 1 2月 2024

指纹

探究 'GCSA: A New Adversarial Example-Generating Scheme Toward Black-Box Adversarial Attacks' 的科研主题。它们共同构成独一无二的指纹。

引用此