Perception-Driven Imperceptible Adversarial Attack Against Decision-Based Black-Box Models
Shenyi Zhang, Baolin Zheng, Peipei Jiang, Lingchen Zhao, Chao Qun Shen, Qian Wang · IEEE Transactions on Information Forensics and Security · 2024
Adversarial examples (AEs) pose significant threats to deep neural networks (DNNs), as they can deceive models into making incorrect predictions through craftily-designed malicious perturbations. The emergence of decision-based attacks, which rely solely on the top-1 decision label, further increases risks for real-world black-box models. Currently, the prevailing practice for generating effective AEs in decision-based attacks involves penalizing adversarial perturbations using the ℓp-norm. However, this approach often fails to consider the human perception of adversarial perturbations in real-world scenarios. To tackle this issue, we propose a novel and efficient Imperceptible Decision-based Black-box Attack (IDBA). Our method prioritizes optimizing the perception-related distribution of perturbations, rather than solely focusing on the ℓp-norm. Specifically, IDBA analyzes the perceptual preferences of both models and the human vision system, selectively perturbing components that influence model decisions yet remain imperceptible to human eyes. Extensive experiments demonstrate the superior performance of IDBA in both invisibility and query efficiency, a widely used metric in prior works, in comparison to state-of-the-art methods. With only 4.8K queries, IDBA achieves a Feature SIMilarity (FSIM) score of 0.92 while reducing the Learned Perceptual Image Patch Similarity (LPIPS) to 0.12, indicating remarkable imperceptibility.