{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/towards-query-efficient-black-box-attacks-an","title":"Towards Query Efficient Black-box Attacks: An Input-free Perspective","arxiv_id":"1809.02918","date":"2018-09-09","proceeding":null,"authors":["Yali Du","Meng Fang","Jin-Feng Yi","Jun Cheng","DaCheng Tao"],"abstract":"Recent studies have highlighted that deep neural networks (DNNs) are\nvulnerable to adversarial attacks, even in a black-box scenario. However, most\nof the existing black-box attack algorithms need to make a huge amount of\nqueries to perform attacks, which is not practical in the real world. We note\none of the main reasons for the massive queries is that the adversarial example\nis required to be visually similar to the original image, but in many cases,\nhow adversarial examples look like does not matter much. It inspires us to\nintroduce a new attack called \\emph{input-free} attack, under which an\nadversary can choose an arbitrary image to start with and is allowed to add\nperceptible perturbations on it. Following this approach, we propose two\ntechniques to significantly reduce the query complexity. First, we initialize\nan adversarial example with a gray color image on which every pixel has roughly\nthe same importance for the target model. Then we shrink the dimension of the\nattack space by perturbing a small region and tiling it to cover the input\nimage. To make our algorithm more effective, we stabilize a projected gradient\nascent algorithm with momentum, and also propose a heuristic approach for\nregion size selection. Through extensive experiments, we show that with only\n1,701 queries on average, we can perturb a gray image to any target class of\nImageNet with a 100\\% success rate on InceptionV3. Besides, our algorithm has\nsuccessfully defeated two real-world systems, the Clarifai food detection API\nand the Baidu Animal Identification API.","url_abs":"http://arxiv.org/abs/1809.02918v1","url_pdf":"http://arxiv.org/pdf/1809.02918v1.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"towards-query-efficient-black-box-attacks-an","repo_url":"https://github.com/yalidu/input-free-attack","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":1,"framework":"tf","reach":null}],"tasks":[],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":null,"atlas_url":null,"mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}