An adaptive black box attack algorithm based on improved differential evolution

Ran Zhang, Yifan Wang, Yifeng Yin
{"title":"An adaptive black box attack algorithm based on improved differential evolution","authors":"Ran Zhang, Yifan Wang, Yifeng Yin","doi":"10.1109/ISPDS56360.2022.9874005","DOIUrl":null,"url":null,"abstract":"As an important part of artificial intelligence technology, deep learning is widely used in various fields of contemporary society. The security of deep learning directly affects the effectiveness of its application in different fields. Effective attack algorithms can evaluate the security of deep learning models, and black box attacks are one of the important methods for testing the security of deep learning algorithms. An adaptive black box attack algorithm based on improved differential evolution is proposed to solve the problems of many queries, difficult selection of attack points that may cause higher attack costs in applications. The algorithm sets the variation factor as a linear decreasing function, uses the fitness function to adaptively control the change of the cross probability factor to improve the global search ability and accelerate the convergence rate, proposes a new variation strategy to enhance the ability of global search and local exploitation and the accuracy of searching attack points, and optimizes the loss function and the calculation method of gradient for defining decisions in deep learning models to improve the effectiveness and efficiency of black box attacks. The results of the comparison experiments show that the attack success rate is effectively improved and the average time and the average number of queries are reduced with the same attack success rate.","PeriodicalId":280244,"journal":{"name":"2022 3rd International Conference on Information Science, Parallel and Distributed Systems (ISPDS)","volume":"23 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-07-22","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2022 3rd International Conference on Information Science, Parallel and Distributed Systems (ISPDS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ISPDS56360.2022.9874005","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

As an important part of artificial intelligence technology, deep learning is widely used in various fields of contemporary society. The security of deep learning directly affects the effectiveness of its application in different fields. Effective attack algorithms can evaluate the security of deep learning models, and black box attacks are one of the important methods for testing the security of deep learning algorithms. An adaptive black box attack algorithm based on improved differential evolution is proposed to solve the problems of many queries, difficult selection of attack points that may cause higher attack costs in applications. The algorithm sets the variation factor as a linear decreasing function, uses the fitness function to adaptively control the change of the cross probability factor to improve the global search ability and accelerate the convergence rate, proposes a new variation strategy to enhance the ability of global search and local exploitation and the accuracy of searching attack points, and optimizes the loss function and the calculation method of gradient for defining decisions in deep learning models to improve the effectiveness and efficiency of black box attacks. The results of the comparison experiments show that the attack success rate is effectively improved and the average time and the average number of queries are reduced with the same attack success rate.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
一种基于改进差分进化的自适应黑盒攻击算法
作为人工智能技术的重要组成部分,深度学习被广泛应用于当代社会的各个领域。深度学习的安全性直接影响其在不同领域应用的有效性。有效的攻击算法可以评估深度学习模型的安全性,黑盒攻击是测试深度学习算法安全性的重要方法之一。针对应用中查询数多、攻击点选择困难、攻击代价高的问题,提出了一种基于改进差分进化的自适应黑盒攻击算法。该算法将变异因子设置为线性递减函数,利用适应度函数自适应控制交叉概率因子的变化,提高了全局搜索能力,加快了收敛速度,提出了一种新的变异策略,增强了全局搜索和局部利用的能力,提高了攻击点搜索的准确性。优化了深度学习模型中定义决策的损失函数和梯度计算方法,提高了黑盒攻击的有效性和效率。对比实验结果表明,在相同的攻击成功率下,有效地提高了攻击成功率,减少了平均查询时间和平均查询次数。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Research on Intelligent Quality Inspection of Customer Service Under the “One Network” Operation Mode of Toll Roads Application of AE keying technology in film and television post-production Study on Artifact Classification Identification Based on Deep Learning Design of Real-time Target Detection System in CCD Vertical Target Coordinate Measurement An evaluation method of municipal pipeline cleaning effect based on image processing
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1