Reverse Margin Inference Attack: Overcoming Adversarial Robustness via Margin Loss Manipulation

Jingyi Li, Jinliang Xue · 2024

Deep neural networks (DNNs) have shown remarkable success in many domains but remain vulnerable to adversarial attacks that exploit slight perturbations in input data to deceive models. This paper introduces a novel adversarial attack method, Reverse Margin Inference Attack (RMIA), which targets defenses that manipulate the margin loss curve. RMIA utilizes Linear Reverse and Sine Reverse transformations to effectively counteract these defenses by restoring the original margin loss, thereby enhancing attack success. Experimental results on CIFAR-10 and ImageNet datasets demonstrate that RMIA significantly reduces model accuracy while improving query efficiency compared to traditional attacks. RMIA's effectiveness is evident across various defensive strategies, showcasing its robustness and efficiency. These findings underscore RMIA's potential to provide new insights into advancing adversarial attack methodologies and challenging existing defensive mechanisms.

Read the paper · More papers on PaperTik