Skip to main navigation Skip to search Skip to main content

An efficient general black-box adversarial attack approach based on multi-objective optimization for high dimensional images

Research output: Contribution to journalArticlepeer-review

Abstract

In black-box scenarios, the adversarial attack algorithms based on iterative optimization perform best. But it may give a false sense of model robustness due to the design of inefficient queries. The adversarial attack algorithm based on multi-objective evolution optimization has been proven to be very effective for the low-dimensional images. However, when the attack space dramatically increases for the high-dimensional color images, the evolutionary efficiency is limited, and it needs more inefficient queries to generate adversarial examples. In this paper, we propose an efficient black-box adversarial attack approach for high dimensional images based on multi-objective optimization (MOO-HD), which includes some novel strategies to solve the above problems. We also propose the strategy of “The transformation of the pixel block with a random step size” to reduce the attack space. The experimental results on three image datasets with different dimensions show that our algorithm can achieve a higher success rate with fewer queries.

Original languageEnglish
Article number107402
JournalComputers and Electrical Engineering
Volume95
DOIs
StatePublished - Oct 2021
Externally publishedYes

Keywords

  • Adversarial examples
  • Black-box attack
  • High dimension
  • Multi-objective optimization

Fingerprint

Dive into the research topics of 'An efficient general black-box adversarial attack approach based on multi-objective optimization for high dimensional images'. Together they form a unique fingerprint.

Cite this