JOURNAL ARTICLE

Data-free Universal Adversarial Perturbation and Black-box Attack

Chaoning ZhangPhilipp BenzAdil KarjauvIn So Kweon

Year: 2021 Journal:   2021 IEEE/CVF International Conference on Computer Vision (ICCV) Pages: 7848-7857

Abstract

Universal adversarial perturbation (UAP), i.e. a single perturbation to fool the network for most images, is widely recognized as a more practical attack because the UAP can be generated beforehand and applied directly during the at-tack stage. One intriguing phenomenon regarding untargeted UAP is that most images are misclassified to a dominant label. This phenomenon has been reported in previous works while lacking a justified explanation, for which our work attempts to provide an alternative explanation. For a more practical universal attack, our investigation of untargeted UAP focuses on alleviating the dependence on the original training samples, from removing the need for sample labels to limiting the sample size. Towards strictly data-free untargeted UAP, our work proposes to exploit artificial Jigsaw images as the training samples, demonstrating competitive performance. We further investigate the possibility of exploiting the UAP for a data-free black-box attack which is arguably the most practical yet challenging threat model. We demonstrate that there exists optimization-free repetitive patterns which can successfully attack deep models. Code is available at https://bit.ly/3y0ZTIC.

Keywords:
Exploit Computer science Adversarial system Limiting Phenomenon Perturbation (astronomy) Artificial intelligence Computer security Theoretical computer science Machine learning Data mining Algorithm Engineering

Metrics

57
Cited By
5.52
FWCI (Field Weighted Citation Impact)
105
Refs
0.97
Citation Normalized Percentile
Is in top 1%
Is in top 10%

Citation History

Topics

Adversarial Robustness in Machine Learning
Physical Sciences →  Computer Science →  Artificial Intelligence
Bacillus and Francisella bacterial research
Life Sciences →  Biochemistry, Genetics and Molecular Biology →  Molecular Biology
Anomaly Detection Techniques and Applications
Physical Sciences →  Computer Science →  Artificial Intelligence
© 2026 ScienceGate Book Chapters — All rights reserved.