2017

Query-Efficient Black-box Adversarial Examples (superceded)

Ilyas, Andrew, Engstrom, Logan, Athalye, Anish et al.

Understand

Note that this paper is superceded by "Black-Box Adversarial Attacks with Limited Queries and Information." Current neural network-based image classifiers are susceptible to adversarial examples, even in the black-box setting, where the attacker is limited to query access without access to gradients.

  • Previous methods --- substitute networks and coordinate-based finite-difference methods --- are either unreliable or query-inefficient, making these methods impractical for certain problems.
  • We introduce a new method for reliably generating adversarial examples under more restricted, practical black-box threat models.
  • First, we apply natural evolution strategies to perform black-box attacks using two to three orders of magnitude fewer queries than previous methods.

Built on

  • A concentration theorem for projections

    S. Dasgupta, D. Hsu, and N. Verma · 2006

    Earlier work this paper cites.

  • Intriguing properties of neural networks

    C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus · 2013

    Earlier work this paper cites.

  • Natural evolution strategies

    D. Wierstra, T. Schaul, T. Glasmachers, Y. Sun, J. Peters, and J. Schmidhuber · 2014

    Earlier work this paper cites.

  • Explaining and harnessing adversarial examples

    I. J. Goodfellow, J. Shlens, and C. Szegedy · 2015

    Earlier work this paper cites.

  • Rethinking the inception architecture for computer vision

    C. Szegedy, V. Vanhoucke, S. Ioffe, J. Shlens, and Z. Wojna · 2015

    Earlier work this paper cites.

  • Hidden voice commands

    N. Carlini, P. Mishra, T. Vaidya, Y. Zhang, M. Sherr, C. Shields, D. Wagner, and W. Zhou · 2016

    Earlier work this paper cites.

Similar

  • Approximation with random bases

    A. N. Gorban, I. Y. Tyukin, D. V. Prokhorov, and K. I. Sofeikov · 2016

    Cited alongside, same era.

  • Adversarial examples in the physical world

    A. Kurakin, I. Goodfellow, and S. Bengio · 2016

    Cited alongside, same era.

  • Transferability in machine learning: from phenomena to black-box attacks using adversarial samples

    N. Papernot, P. McDaniel, and I. Goodfellow · 2016

    Cited alongside, same era.

  • Synthesizing robust adversarial examples

    A. Athalye, L. Engstrom, A. Ilyas, and K. Kwok · 2017

    Cited alongside, same era.

  • Towards evaluating the robustness of neural networks

    N. Carlini and D. Wagner · 2017

    Cited alongside, same era.

  • Zoo: Zeroth order optimization based black-box attacks to deep neural networks without training substitute models

    P.-Y. Chen, H. Zhang, Y. Sharma, J. Yi, and C.-J. Hsieh · 2017

    Cited alongside, same era.

Then

  • Machine learning as an adversarial service: Learning black-box adversarial examples

    J. Hayes and G. Danezis · 2017

    Closest in time.

  • Delving into transferable adversarial examples and black-box attacks

    Y. Liu, X. Chen, C. Liu, and D. Song · 2017

    Closest in time.

  • Towards deep learning models resistant to adversarial attacks

    A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu · 2017

    Closest in time.

  • Random gradient-free minimization of convex functions

    Y. Nesterov and V. Spokoiny · 2017

    Closest in time.

  • Practical black-box attacks against machine learning

    N. Papernot, P. McDaniel, I. Goodfellow, S. Jha, Z. B. Celik, and A. Swami · 2017

    Closest in time.

  • Evolution strategies as a scalable alternative to reinforcement learning

    Original

    T. Salimans, J. Ho, X. Chen, and I. Sutskever · 2017

    Closest in time.

Beyond the bibliography

alphaXiv searches the wider corpus for related work and actual follow-ups.

Open on alphaXiv

alphaXiv is searching for related work…