2018/05/28 by Moustafa Alzantot, Alzantot, Moustafa, Yash Sharma +10 · 25 citations
Computer Science · Mathematics · #Adversarial Robustness in Machine Learning #Adversarial system #Anomaly Detection Techniques and Applications #Artificial Intelligence (cs.AI) #Artificial intelligence #Artificial neural network #Black box #Computer Vision and Pattern Recognition (cs.CV) #Computer science #Cryptography and Security (cs.CR) #Deep learning #Deep neural networks #Differentiable function #Domain Adaptation and Few-Shot Learning #FOS: Computer and information sciences #Image (mathematics) #MNIST database #Machine Learning (cs.LG) #Machine learning #Mathematics #cs.AI #cs.CR #cs.CV #cs.LG
paper · pdf · doi:10.48550/arxiv.1805.11090
published in arXiv (Cornell University) (Cornell University) · Accepted in The Genetic and Evolutionary Computation Conference (GECCO) 2019
openalex publication_date 2018/05/28 · arxiv created 2019/07/01 · arxiv updated 2019/07/02 · openalex created_date 2025/10/10 · openalex updated_date 2026/08/08
Deep neural networks are vulnerable to adversarial examples, even in the black-box setting, where the attacker is restricted solely to query access. Existing black-box approaches to generating adversarial examples typically require a significant number of queries, either for training a substitute network or performing gradient estimation. We introduce GenAttack, a gradient-free optimization technique that uses genetic algorithms for synthesizing adversarial examples in the black-box setting. Our experiments on different datasets (MNIST, CIFAR-10, and ImageNet) show that GenAttack can successfully generate visually imperceptible adversarial examples against state-of-the-art image recognition models with orders of magnitude fewer queries than previous approaches. Against MNIST and CIFAR-10 models, GenAttack required roughly 2,126 and 2,568 times fewer queries respectively, than ZOO, the prior state-of-the-art black-box attack. In order to scale up the attack to large-scale high-dimensional ImageNet models, we perform a series of optimizations that further improve the query efficiency of our attack leading to 237 times fewer queries against the Inception-v3 model than ZOO. Furthermore, we show that GenAttack can successfully attack some state-of-the-art ImageNet defenses, including ensemble adversarial training and non-differentiable or randomized input transformations. Our results suggest that evolutionary algorithms open up a promising area of research into effective black-box attacks.