vix.ing · top · new · best · stats · spec

Query-limited Black-box Attacks to Classifiers

2017/12/23 by Fnu Suya, Yuan Tian, Suya, Fnu +5 · 2 citations
Computer Science · #Advanced Malware Detection Techniques #Adversarial Robustness in Machine Learning #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #Machine Learning (cs.LG) #Machine Learning (stat.ML) #Network Security and Intrusion Detection

paper · pdf · doi:10.48550/arxiv.1712.08713

openalex publication_date 2017/12/23 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/28

Abstract

We study black-box attacks on machine learning classifiers where each query to the model incurs some cost or risk of detection to the adversary. We focus explicitly on minimizing the number of queries as a major objective. Specifically, we consider the problem of attacking machine learning classifiers subject to a budget of feature modification cost while minimizing the number of queries, where each query returns only a class and confidence score. We describe an approach that uses Bayesian optimization to minimize the number of queries, and find that the number of queries can be reduced to approximately one tenth of the number needed through a random strategy for scenarios where the feature modification cost budget is low.

Citations

Cited by

Related