Conference proceeding
On the Design of Black-Box Adversarial Examples by Leveraging Gradient-Free Optimization and Operator Splitting Method
2019 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2019), v 2019-, pp 121-130
01 Jan 2019
Featured in Collection : UN Sustainable Development Goals @ Drexel
Abstract
Robust machine learning is currently one of the most prominent topics which could potentially help shaping a future of advanced AI platforms that not only perform well in average cases but also in worst cases or adverse situations. Despite the long-term vision, however, existing studies on black-box adversarial attacks are still restricted to very specific settings of threat models (e.g., single distortion metric and restrictive assumption on target model's feedback to queries) and/or suffer from prohibitively high query complexity. To push for further advances in this field, we introduce a general framework based on an operator splitting method, the alternating direction method of multipliers (ADMM) to devise efficient, robust black-box attacks that work with various distortion metrics and feedback settings without incurring high query complexity. Due to the black-box nature of the threat model, the proposed ADMM solution framework is integrated with zeroth-order (ZO) optimization and Bayesian optimization (BO), and thus is applicable to the gradient-free regime. This results in two new black-box adversarial attack generation methods, ZO-ADMM and BO-ADMM. Our empirical evaluations on image classification datasets show that our proposed approaches have much lower function query complexities compared to state-of-the-art attack methods, but achieve very competitive attack success rates.
Metrics
Details
- Title
- On the Design of Black-Box Adversarial Examples by Leveraging Gradient-Free Optimization and Operator Splitting Method
- Creators
- Pu Zhao - Northeastern UniversitySijia Liu - IBM (Denmark)Pin-Yu Chen - IBM (United States)Trong Nghia Hoang - IBM Res, MIT IBM Watson AI Lab, Cambridge, MA USAKaidi Xu - Northeastern UniversityBhavya Kailkhura - Syracuse UniversityXue Lin - Northeastern University
- Publication Details
- 2019 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2019), v 2019-, pp 121-130
- Series
- IEEE International Conference on Computer Vision
- Publisher
- IEEE
- Number of pages
- 10
- Grant note
- CNS-1932351 / National Science Foundation; National Science Foundation (NSF)
- Resource Type
- Conference proceeding
- Language
- English
- Academic Unit
- Computer Science
- Web of Science ID
- WOS:000531438100013
- Scopus ID
- 2-s2.0-85081903378
- Other Identifier
- 991021871482604721
UN Sustainable Development Goals (SDGs)
This publication has contributed to the advancement of the following goals:
Source: SDGs in the Output
InCites Highlights
Data related to this publication, from InCites Benchmarking & Analytics tool:
- Collaboration types
- Industry collaboration
- Domestic collaboration
- Web of Science research areas
- Computer Science, Artificial Intelligence
- Engineering, Electrical & Electronic