<p>Deep neural networks are known to be vulnerable to adversarial attacks. Research indicates that unrestricted attack methods tend to produce more natural-looking adversarial examples than restricted attack methods. However, existing unrestricted query-based black-box attack methods usually require a large number of queries but exhibit a low attack success rate and poor transferability. To address these issues, we propose a fast yet effective unrestricted query-based black-box attack method named Fast-ColorFool which consists of a complementary color attack strategy and a cumulative perturbation strategy. Specifically, we first put forward the complementary color attack strategy which is executed on the Hue channel of HSV color space for the first-step attack, and theoretical proof for the effectiveness of the complementary color attack strategy is provided. Then, we design the cumulative perturbation strategy to generate adversarial examples iteratively. This strategy is operated on the a and b channels of Lab color space. It is worth mentioning that both our complementary color attack strategy and our cumulative perturbation strategy can also be integrated into many other unrestricted methods. Extensive experiments demonstrate our method’s superiority over state-of-the-art approaches in terms of attack success rate, transferability, and number of queries. For example, on the ImageNet dataset, the proposed method achieves an average query attack success rate of 95.2% and an average transfer attack success rate of 49.5% on four classifiers (AlexNet, ResNet18, ResNet50, and ViT-Base/16), while only using an average of 176.8 queries.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Fast-colorfool: faster and more transferable semantic adversarial attack with complementary colors and cumulative perturbation

  • Shihui Zhang,
  • Xueqiang Han,
  • Zhiguo Cui,
  • Sheng Zhan,
  • Qing Tian

摘要

Deep neural networks are known to be vulnerable to adversarial attacks. Research indicates that unrestricted attack methods tend to produce more natural-looking adversarial examples than restricted attack methods. However, existing unrestricted query-based black-box attack methods usually require a large number of queries but exhibit a low attack success rate and poor transferability. To address these issues, we propose a fast yet effective unrestricted query-based black-box attack method named Fast-ColorFool which consists of a complementary color attack strategy and a cumulative perturbation strategy. Specifically, we first put forward the complementary color attack strategy which is executed on the Hue channel of HSV color space for the first-step attack, and theoretical proof for the effectiveness of the complementary color attack strategy is provided. Then, we design the cumulative perturbation strategy to generate adversarial examples iteratively. This strategy is operated on the a and b channels of Lab color space. It is worth mentioning that both our complementary color attack strategy and our cumulative perturbation strategy can also be integrated into many other unrestricted methods. Extensive experiments demonstrate our method’s superiority over state-of-the-art approaches in terms of attack success rate, transferability, and number of queries. For example, on the ImageNet dataset, the proposed method achieves an average query attack success rate of 95.2% and an average transfer attack success rate of 49.5% on four classifiers (AlexNet, ResNet18, ResNet50, and ViT-Base/16), while only using an average of 176.8 queries.