Current neural network-based classifiers are susceptible to adversarial examples even in the black-box setting, where the attacker could only query the output of the network. We present a new method for black-box adversarial attack. Unlike previous methods that combined transfer-based and scored-based methods by using the gradient or initialization of a surrogate white-box model, this new method tries to learn a low-dimensional embedding using a pretrained model, and then performs efficient search within the embedding space to attack an unknown target network. The method produces adversarial perturbations with high level semantic patterns that are easily transferable. We show that this approach can greatly improve the query efficiency of black-box adversarial attack across different target network architectures. We evaluate our approach on MNIST, ImageNet and Google Cloud Vision API, resulting in a significant reduction on the number of queries. We also attack adversarially defended networks on CIFAR10 and ImageNet, where our method not only reduces the number of queries, but also improves the attack success rate.
5月15日
3pm - 4pm
地點
https://hkust.zoom.us/j/98874789179
講者/表演者
Mr. Zhichao HUANG
HKUST
主辦單位
Department of Mathematics
聯絡方法
mathseminar@ust.hk
付款詳情
對象
Alumni, Faculty and Staff, PG Students, UG Students
語言
英語
其他活動
5月24日
研討會, 演講, 講座
IAS / School of Science Joint Lecture - Confinement Controlled Electrochemistry: Nanopore beyond Sequencing
Abstract Nanopore electrochemistry refers to the promising measurement science based on elaborate pore structures, which offers a well-defined geometric confined space to adopt and characterize sin...
5月13日
研討會, 演講, 講座
IAS / School of Science Joint Lecture – Expanding the Borders of Chemical Reactivity
Abstract The lecture will demonstrate how it has been possible to expand the borders of cycloadditions beyond the “classical types of cycloadditions” applying organocatalytic activation principles....