Abstract

Decision-based methods have shown to be effective in black-box adversarial attacks, as they can obtain satisfactory performance and only require to access the final model prediction. Gradient estimation is a critical step in black-box adversarial attacks, as it will directly affect the query efficiency. Recent works have attempted to utilize gradient priors to facilitate score-based methods to obtain better results. However, these gradient priors still suffer from the edge gradient discrepancy issue and the successive iteration gradient direction issue, thus are difficult to simply extend to decision-based methods. In this paper, we propose a novel Decision-based Black-box Attack framework with Gradient Priors (DBA-GP), which seamlessly integrates the data-dependent gradient prior and time-dependent prior into the gradient estimation procedure. First, by leveraging the joint bilateral filter to deal with each random perturbation, DBA-GP can guarantee that the generated perturbations in edge locations are hardly smoothed, i.e., alleviating the edge gradient discrepancy, thus remaining the characteristics of the original image as much as possible. Second, by utilizing a new gradient updating strategy to automatically adjust the successive iteration gradient direction, DBA-GP can accelerate the convergence speed, thus improving the query efficiency. Extensive experiments have demonstrated that the proposed method outperforms other strong baselines significantly.

Keywords:
Prior probability Computer science Black box Gradient boosting Algorithm Mathematical optimization Artificial intelligence Mathematics Bayesian probability Random forest

Metrics

1
Cited By
0.26
FWCI (Field Weighted Citation Impact)
35
Refs
0.56
Citation Normalized Percentile
Is in top 1%
Is in top 10%

Citation History

Topics

Adversarial Robustness in Machine Learning
Physical Sciences →  Computer Science →  Artificial Intelligence
Anomaly Detection Techniques and Applications
Physical Sciences →  Computer Science →  Artificial Intelligence
Bacillus and Francisella bacterial research
Life Sciences →  Biochemistry, Genetics and Molecular Biology →  Molecular Biology

Related Documents

JOURNAL ARTICLE

Black-box Bayesian adversarial attack with transferable priors

Shudong ZhangHaichang GaoChao ShuXiwen CaoYunyi ZhouJianping He

Journal:   Machine Learning Year: 2022 Vol: 113 (4)Pages: 1511-1528
JOURNAL ARTICLE

Boosting Black-box Adversarial Attack with a Better Convergence

Heng YinJindong WangYan MiXiaoning Zhang

Journal:   2020 5th International Conference on Mechanical, Control and Computer Engineering (ICMCCE) Year: 2020 Pages: 1238-1242
JOURNAL ARTICLE

Boosting Black-Box Attack with Partially Transferred Conditional Adversarial Distribution

Feng YanBaoyuan WuYanbo FanLi LiuZhifeng LiShu‐Tao Xia

Journal:   2022 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) Year: 2022 Pages: 15074-15083
© 2026 ScienceGate Book Chapters — All rights reserved.