Prior convictions: Black-box adversarial attacks with bandits and priors
Name
1807.07978.pdf
Description
Accepted version
Size
954.7 KB
Format
Adobe PDF
Checksum (MD5)
ad1d9de95396121e824984235b872a0a
Author(s) • •
Ilyas, Andrew.
Engstrom, Logan G.
Madry, Aleksander
Date Issued
March 2019
Journal
7th International Conference on Learning Representations
Publisher
arXiv
Citation
Ilyas, Andrew et al. "Prior convictions: Black-box adversarial attacks with bandits and priors." 7th International Conference on Learning Representations (March 2019); © 7th International Conference on Learning Representations, ICLR 2019. All Rights Reserved.
Version
Author's final manuscript
Abstract
We study the problem of generating adversarial examples in a black-box setting in which only loss-oracle access to a model is available. We introduce a framework that conceptually unifies much of the existing work on black-box attacks, and we demonstrate that the current state-of-the-art methods are optimal in a natural sense. Despite this optimality, we show how to improve black-box attacks by bringing a new element into the problem: gradient priors. We give a bandit optimization-based algorithm that allows us to seamlessly integrate any such priors, and we explicitly identify and incorporate two examples. The resulting methods use two to four times fewer queries and fail two to five times less than the current state-of-the-art.
MIT Department
MIT-IBM Watson AI Lab
Terms of Use
Creative Commons Attribution-Noncommercial-Share Alike
Persistent DSpace Link
DOI of Published Version
https://openreview.net/forum?id=BkMiWhR5K7