Skip to main navigation Skip to search Skip to main content

An Adversarial Attack Based on Multi-objective Optimization in the Black-Box Scenario: MOEA-APGA II

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Various approaches have been proposed to exploit the vulnerability to challenge the robustness of victim models, in the black-box scenario, it is difficult to generate barely noticeable adversarial examples while guaranteeing the attack success rate. Although some methods could solve this problem to some extent, the imperceptibility of the generated perturbations is still far from that of the most advanced attack, worse still, it is infeasible to attack the color image datasets due to its inefficiency. In MOEA-APGA II, We propose the new objective function and the novel population evolution strategies to reduce the average distortion without sacrificing the attack success rate, and compared to the state-of-the-art black-box attack (ZOO), our method achieves a better attack success rate under fewer queries on the benchmark datasets.

Original languageEnglish
Title of host publicationInformation and Communications Security - 21st International Conference, ICICS 2019, Revised Selected Papers
EditorsJianying Zhou, Xiapu Luo, Qingni Shen, Zhen Xu
PublisherSpringer
Pages603-612
Number of pages10
ISBN (Print)9783030415785
DOIs
StatePublished - 2020
Externally publishedYes
Event21st International Conference on Information and Communications Security, ICICS 2019 - Beijing, China
Duration: 15 Dec 201917 Dec 2019

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume11999 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference21st International Conference on Information and Communications Security, ICICS 2019
Country/TerritoryChina
CityBeijing
Period15/12/1917/12/19

Keywords

  • Adversarial examples
  • Black-box attack
  • Multi-objective optimization

Fingerprint

Dive into the research topics of 'An Adversarial Attack Based on Multi-objective Optimization in the Black-Box Scenario: MOEA-APGA II'. Together they form a unique fingerprint.

Cite this