Adversarial Attack on Attackers: Post-Process to Mitigate Black-Box Score-Based Query Attacks
–Neural Information Processing Systems
The score-based query attacks (SQAs) pose practical threats to deep neural networks by crafting adversarial perturbations within dozens of queries, only using the model's output scores. Nonetheless, we note that if the loss trend of the outputs is slightly perturbed, SQAs could be easily misled and thereby become much less effective. Following this idea, we propose a novel defense, namely Adversarial Attack on Attackers (AAA), to confound SQAs towards incorrect attack directions by slightly modifying the output logits. In this way, (1) SQAs are prevented regardless of the model's worst-case robustness; (2) the original model predictions are hardly changed, i.e., no degradation on clean accuracy; (3) the calibration of confidence scores can be improved simultaneously. Extensive experiments are provided to verify the above advantages.
Neural Information Processing Systems
Oct-11-2024, 07:08:38 GMT
- Industry:
- Government > Military (0.64)
- Information Technology > Security & Privacy (0.64)
- Transportation > Air (0.40)
- Technology: