A Model-Based Derivative-Free Approach to Black-Box Adversarial Examples: BOBYQA

02/24/2020
by   Giuseppe Ughi, et al.
0

We demonstrate that model-based derivative free optimisation algorithms can generate adversarial targeted misclassification of deep networks using fewer network queries than non-model-based methods. Specifically, we consider the black-box setting, and show that the number of networks queries is less impacted by making the task more challenging either through reducing the allowed ℓ^∞ perturbation energy or training the network with defences against adversarial misclassification. We illustrate this by contrasting the BOBYQA algorithm with the state-of-the-art model-free adversarial targeted misclassification approaches based on genetic, combinatorial, and direct-search algorithms. We observe that for high ℓ^∞ energy perturbations on networks, the aforementioned simpler model-free methods require the fewest queries. In contrast, the proposed BOBYQA based method achieves state-of-the-art results when the perturbation energy decreases, or if the network is trained against adversarial perturbations.

READ FULL TEXT
research
12/03/2020

An Empirical Study of Derivative-Free-Optimization Algorithms for Targeted Black-Box Attacks in Deep Neural Networks

We perform a comprehensive study on the performance of derivative free o...
research
09/09/2021

Energy Attack: On Transferring Adversarial Examples

In this work we propose Energy Attack, a transfer-based black-box L_∞-ad...
research
05/20/2018

Targeted Adversarial Examples for Black Box Audio Systems

The application of deep recurrent networks to audio transcription has le...
research
02/18/2020

On the Matrix-Free Generation of Adversarial Perturbations for Black-Box Attacks

In general, adversarial perturbations superimposed on inputs are realist...
research
02/12/2020

Targeted free energy estimation via learned mappings

Free energy perturbation (FEP) was proposed by Zwanzig more than six dec...
research
06/24/2023

Learned Mappings for Targeted Free Energy Perturbation between Peptide Conformations

Targeted free energy perturbation uses an invertible mapping to promote ...
research
02/23/2023

Accurate Free Energy Estimations of Molecular Systems Via Flow-based Targeted Free Energy Perturbation

The Targeted Free Energy Perturbation (TFEP) method aims to overcome the...

Please sign up or login with your details

Forgot password? Click here to reset