Black-box decision based adversarial attack with symmetric α-stable distribution

Vignesh Srinivasan, Ercan E. Kuruoglu, Klaus Robert Müller, Wojciech Samek, Shinichi Nakajima

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

Developing techniques for adversarial attack and defense is an important research field for establishing reliable machine learning and its applications. Many existing methods employ Gaussian random variables for exploring the data space to find the most adversarial (for attacking) or least adversarial (for defense) point. However, the Gaussian distribution is not necessarily the optimal choice when the exploration is required to follow the complicated structure that most real-world data distributions exhibit. In this paper, we investigate how statistics of random variables affect such random walk exploration. Specifically, we generalize the Boundary Attack, a state-of-the-art blackbox decision based attacking strategy, and propose the Lévy-Attack, where the random walk is driven by symmetric α-stable random variables. Our experiments on MNIST and CIFAR10 datasets show that the Lévy-Attack explores the image data space more efficiently, and significantly improves the performance. Our results also give an insight into the recently found fact in the whitebox attacking scenario that the choice of the norm for measuring the amplitude of the adversarial patterns is essential.

Original languageEnglish
Title of host publicationEUSIPCO 2019 - 27th European Signal Processing Conference
PublisherEuropean Signal Processing Conference, EUSIPCO
ISBN (Electronic)9789082797039
DOIs
Publication statusPublished - 2019 Sept
Event27th European Signal Processing Conference, EUSIPCO 2019 - A Coruna, Spain
Duration: 2019 Sept 22019 Sept 6

Publication series

NameEuropean Signal Processing Conference
Volume2019-September
ISSN (Print)2219-5491

Conference

Conference27th European Signal Processing Conference, EUSIPCO 2019
Country/TerritorySpain
CityA Coruna
Period19/9/219/9/6

Keywords

  • Adversarial attack
  • Deep neural networks
  • Image classification
  • α-stable distribution

ASJC Scopus subject areas

  • Signal Processing
  • Electrical and Electronic Engineering

Fingerprint

Dive into the research topics of 'Black-box decision based adversarial attack with symmetric α-stable distribution'. Together they form a unique fingerprint.

Cite this