DeltaBound Attack: Efficient decision-based attack in low queries regime
–arXiv.org Artificial Intelligence
Machine learning systems are not robust against adversarial examples, meticulously crafted perturbation of the inputs that fool the classifier [4, 14, 21, 27, 28]. As Deep Neural Networks and other machine learning models become more and more important in everyday life and safety-critical applications such as autonomous navigation, surveillance systems, medical diagnosis, and malware analysis, it is fundamental to understand their robustness in the worst-case scenario. Evaluating the robustness of models is extremely challenging, so it is critical to develop stronger adversarial attacks to better understand the limits and capabilities of machine learning models. Many adversarial attacks have been proposed, however, many of them focus on the white-box setting, where the attacker has full knowledge of the victim model. However, in the real world scenario, generally, the attacker knows neither the kind of models used nor the weights and parameters of the models. To overcome the limitations of the white-box setting various black-box settings were defined. In the black-box settings, generally, the attacker has limited information about the model and the defender architecture, for example, it might not know the weights of the model or it has no access to the gradient of the model. In addition, adversarial attacks can be targeted (in this case the goal is to cause the model to classify the samples to a chosen class) or untargeted (in this case the goal is to cause the model to classify the samples to a different class from the initial ones).
arXiv.org Artificial Intelligence
Oct-1-2022
- Country:
- North America > United States
- Wisconsin (0.05)
- Asia > Middle East
- Jordan (0.04)
- North America > United States
- Genre:
- Research Report (0.50)
- Industry:
- Information Technology > Security & Privacy (1.00)
- Technology: