Towards Score-Based Black-Box Adversarial Examples Attack in Real World
摘要
Adversarial example (AE) attacks pose significant threats to the development of Deep Neural Networks (DNNs). While there has been extensive research on adversarial attacks targeting the physical world under the white-box setting in recent years, the black-box setting, which is more aligned with practical deployment scenarios, remains relatively underexplored. In this paper, we propose SPA (Score-based Physical-world Attack), which can achieve black-box attacks employing 3 strategies, i.e., Target Attack (TA), Non-target Attack (NTA), and Appearance Attack (AA), in the physical world. Experimental results substantiate the efficacy and robustness of SPA across diverse real-world scenarios, making a contribution to the establishment of vulnerability repositories for DNNs in the physical world.