{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/red-attack-resource-efficient-decision-based","title":"RED-Attack: Resource Efficient Decision based Attack for Machine Learning","arxiv_id":"1901.10258","date":"2019-01-29","proceeding":null,"authors":["Faiq Khalid","Hassan Ali","Muhammad Abdullah Hanif","Semeen Rehman","Rehan Ahmed","Muhammad Shafique"],"abstract":"Due to data dependency and model leakage properties, Deep Neural Networks\n(DNNs) exhibit several security vulnerabilities. Several security attacks\nexploited them but most of them require the output probability vector. These\nattacks can be mitigated by concealing the output probability vector. To\naddress this limitation, decision-based attacks have been proposed which can\nestimate the model but they require several thousand queries to generate a\nsingle untargeted attack image. However, in real-time attacks, resources and\nattack time are very crucial parameters. Therefore, in resource-constrained\nsystems, e.g., autonomous vehicles where an untargeted attack can have a\ncatastrophic effect, these attacks may not work efficiently. To address this\nlimitation, we propose a resource efficient decision-based methodology which\ngenerates the imperceptible attack, i.e., the RED-Attack, for a given black-box\nmodel. The proposed methodology follows two main steps to generate the\nimperceptible attack, i.e., classification boundary estimation and adversarial\nnoise optimization. Firstly, we propose a half-interval search-based algorithm\nfor estimating a sample on the classification boundary using a target image and\na randomly selected image from another class. Secondly, we propose an\noptimization algorithm which first, introduces a small perturbation in some\nrandomly selected pixels of the estimated sample. Then to ensure\nimperceptibility, it optimizes the distance between the perturbed and target\nsamples. For illustration, we evaluate it for CFAR-10 and German Traffic Sign\nRecognition (GTSR) using state-of-the-art networks.","url_abs":"http://arxiv.org/abs/1901.10258v2","url_pdf":"http://arxiv.org/pdf/1901.10258v2.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"red-attack-resource-efficient-decision-based","repo_url":"https://github.com/fklodhi/FaDec","is_official":1,"mentioned_in_paper":0,"mentioned_in_github":0,"framework":"none","reach":null}],"tasks":[{"task_slug":"autonomous-vehicles","task_name":"Autonomous Vehicles"},{"task_slug":"machine-learning","task_name":"BIG-bench Machine Learning"},{"task_slug":"classification","task_name":"General Classification"},{"task_slug":"traffic-sign-recognition","task_name":"Traffic Sign Recognition"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":null,"mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}