articleMay 1, 2020GOLD OA
HopSkipJumpAttack: A Query-Efficient Decision-Based Attack
University of California, Berkeley
Indexed incrossref
Abstract
The goal of a decision-based adversarial attack on a trained model is to generate adversarial examples based solely on observing output labels returned by the targeted model. We develop HopSkipJumpAttack, a family of algorithms based on a novel estimate of the gradient direction using binary information at the decision boundary. The proposed family includes both untargeted and targeted attacks optimized for ℓ and ℓ ∞ similarity metrics respectively. Theoretical analysis is provided for the proposed algorithms and the gradient direction estimate. Experiments show HopSkipJumpAttack requires significantly fewer model queries than several state-of-the-art decision-based adversarial attacks. It also achieves…
Citation impact
600
total citations
- FWCI
- 48.12
- Percentile
- 100%
- References
- 76
Citations per year
Authors
3Topics & keywords
Topics
Keywords
- Adversarial system
- Computer science
- Similarity (geometry)
- Decision boundary
- Boundary (topology)
- Binary number
- Artificial intelligence
- State (computer science)
UN Sustainable Development Goals
- Peace, Justice and strong institutions
No related works found for this paper.