SQBA: sequential query-based blackbox attack

Yiyi Tao · 2023

Many existing approaches to blackbox adversarial attacks follow attack strategies with predefined priori which are fixed throughout the process. As a result, they often require an excessive number of queries against the victim models to succeed. In this paper, we proposed a new attacking paradigm that better resembles real-world attacks in practical settings, where an agent (i.e., attacker) approaches the attack by taking actions (i.e., perturbations to the source image) through sequential interactions with the environment (i.e., the victim model) to achieve maximum rewards (i.e., the success of attack with the minimum number of queries). Naturally, as any action the agent chooses to take would alter the query image and change the state of the attack, the agent needs to adapt its policy accordingly along the trajectory instead of applying a predefined strategy unanimously. As an instantiation, we propose a “sequential query-based boundary blackbox attack” (SQBA), which learns a policy to adaptively select from a set of candidates attacking methods and then follow the selected method to apply one attack at each step. For demonstration, we restrict the candidate to subspace-based boundary attack methods. We show that the policy can be learned effectively with a variety of approaches, including imitation learning, policy optimization, and an ensemble of both. Extensive experiments on four benchmark datasets (MNIST, CIFAR-10, CelebA, and ImageNet) show that SQBA can significantly reduce the query complexity under different settings compared with baselines while keeping a 100% attack success rate. In addition, we find that the Reinforcement Learning agent as an ensemble of TRPO and BiLSTM performs the best among different agents.

Read the paper · More papers on PaperTik