Skip to main content

An Adversarial Attack Based on Multi-objective Optimization in the Black-Box Scenario: MOEA-APGA II

  • Conference paper
  • First Online:
Information and Communications Security (ICICS 2019)

Part of the book series: Lecture Notes in Computer Science ((LNSC,volume 11999))

Included in the following conference series:

  • 2851 Accesses

Abstract

Various approaches have been proposed to exploit the vulnerability to challenge the robustness of victim models, in the black-box scenario, it is difficult to generate barely noticeable adversarial examples while guaranteeing the attack success rate. Although some methods could solve this problem to some extent, the imperceptibility of the generated perturbations is still far from that of the most advanced attack, worse still, it is infeasible to attack the color image datasets due to its inefficiency. In MOEA-APGA II, We propose the new objective function and the novel population evolution strategies to reduce the average distortion without sacrificing the attack success rate, and compared to the state-of-the-art black-box attack (ZOO), our method achieves a better attack success rate under fewer queries on the benchmark datasets.

This is a preview of subscription content, log in via an institution to check access.

Access this chapter

Subscribe and save

Springer+ Basic
$34.99 /Month
  • Get 10 units per month
  • Download Article/Chapter or eBook
  • 1 Unit = 1 Article or 1 Chapter
  • Cancel anytime
Subscribe now

Buy Now

Chapter
USD 29.95
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever

Tax calculation will be finalised at checkout

Purchases are for personal use only

Institutional subscriptions

Similar content being viewed by others

Notes

  1. 1.

    In some works, ‘non-target attack’ is also called ‘misclassification’, but in this paper, ‘misclassification’ covers the ‘targeted attack’ and the ‘non-target attack’.

References

  1. Szegedy, C., et al.: Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199 (2013)

  2. Nguyen, A., Yosinski, J., Clune, J.: Deep neural networks are easily fooled: high confidence predictions for unrecognizable images. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Boston, pp. 427–436 (2014)

    Google Scholar 

  3. Akhtar, N., Mian, A.: Threat of adversarial attacks on deep learning in computer vision: a survey. IEEE Access 6, 14410–14430 (2018)

    Article  Google Scholar 

  4. Goodfellow, I.J., Shlens, J., Szegedy, C.: Explaining and harnessing adversarial examples. In: International Conference on Machine Learning, pp. 1–10 (2015)

    Google Scholar 

  5. Papernot, N., Mcdaniel, P., Goodfellow, I., Jha, S., Celik, Z.B., Swami, A.: Practical black-box attacks against deep learning systems using adversarial examples. In: ACM Asia Conference on Computer and Communications Security (2016)

    Google Scholar 

  6. Tu, C.C., et al.: Autozoom: autoencoder-based zeroth order optimization method for attacking black-box neural networks. In: Proceedings of the AAAI Conference on Artificial Intelligence, vol. 33, pp. 742–749 (2019)

    Google Scholar 

  7. Liu, Y., Chen, X., Liu, C., Song, D.: Delving into transferable adversarial examples and black-box attacks. arXiv preprint arXiv:1611.02770 (2016)

  8. Narodytska, N., Kasiviswanathan, S.: Simple black-box adversarial attacks on deep neural networks. In: Computer Vision and Pattern Recognition Workshops, pp. 1310–1318 (2017)

    Google Scholar 

  9. Chen, P.Y., Zhang, H., Sharma, Y., Yi, J., Hsieh, C.J.: Zoo: zeroth order optimization based black-box attacks to deep neural networks without training substitute models. In: Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security, pp. 15–26. ACM (2017)

    Google Scholar 

  10. Su, J., Vargas, D.V., Sakurai, K.: One pixel attack for fooling deep neural networks. IEEE Trans. Evol. Comput. 23(5), 828–841 (2019)

    Article  Google Scholar 

  11. Das, S., Suganthan, P.N.: Differential evolution: a survey of the state-of-the-art. IEEE Trans. Evol. Comput. 15(1), 4–31 (2011)

    Article  Google Scholar 

  12. Deng, Y., Zhang, C., Wang, X.: A multi-objective examples generation approach to fool the deep neural networks in the black-box scenario. In: IEEE International Conference on Data Science in Cyberspace, pp. 92–99. IEEE (2019)

    Google Scholar 

  13. Zhang, Q., Li, H.: MOEA/D: a multiobjective evolutionary algorithm based on decomposition. IEEE Trans. Evol. Comput. 11(6), 712–731 (2007)

    Article  Google Scholar 

  14. Hillermeier, C.: Nonlinear Multiobjective Optimization: A Generalized Homotopy Approach, vol. 135. Springer, Berlin (2001). https://doi.org/10.1007/978-3-0348-8280-4

    Book  MATH  Google Scholar 

  15. Carlini, N., Wagner, D.: Towards evaluating the robustness of neural networks. In: IEEE Symposium on Security and Privacy, pp. 39–57. IEEE (2017)

    Google Scholar 

  16. Sarkar, S., Bansal, A., Mahbub, U., Chellappa, R.: UPSET and ANGRI : Breaking high performance image classifiers. arXiv preprint arXiv:1707.01159 (2017)

Download references

Acknowledgment

This study was supported by the National Key Research and Development Program of China (No.2016YFB0800900) and the Shenzhen Research Council (Grant No.JSGG20170822160842949,GJHZ20180928155209705).

Author information

Authors and Affiliations

Authors

Corresponding author

Correspondence to Chuanyi Liu .

Editor information

Editors and Affiliations

Rights and permissions

Reprints and permissions

Copyright information

© 2020 Springer Nature Switzerland AG

About this paper

Check for updates. Verify currency and authenticity via CrossMark

Cite this paper

Zhang, C., Deng, Y., Guo, X., Wang, X., Liu, C. (2020). An Adversarial Attack Based on Multi-objective Optimization in the Black-Box Scenario: MOEA-APGA II. In: Zhou, J., Luo, X., Shen, Q., Xu, Z. (eds) Information and Communications Security. ICICS 2019. Lecture Notes in Computer Science(), vol 11999. Springer, Cham. https://doi.org/10.1007/978-3-030-41579-2_35

Download citation

  • DOI: https://doi.org/10.1007/978-3-030-41579-2_35

  • Published:

  • Publisher Name: Springer, Cham

  • Print ISBN: 978-3-030-41578-5

  • Online ISBN: 978-3-030-41579-2

  • eBook Packages: Computer ScienceComputer Science (R0)

Publish with us

Policies and ethics