Reinforcement Learning Inspired Black-box Adversarial Attacks for Computer Vision

📅 2026-09-21
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
本文针对神经网络在计算机视觉中对小扰动的脆弱性问题,提出了一种基于强化学习的黑盒对抗攻击方法,通过少量查询优化对抗扰动。
📝 Abstract
Neural networks, both convolution or transformer based, are essential for modern computer vision systems. However, they are vulnerable to small perturbations, almost imperceptible to humans, which significantly alter the model's prediction. These adversarial attacks are often considered to be a significant threat to the implementation of neural networks in safety-critical applications. Most attacks utilize the white-box threat model and therefore require full access to the target model, making them unrealistic to use in practice. We propose a novel approach under the more realistic black-box threat model that utilizes concepts from reinforcement learning to optimize perturbations with a non-differentiable target model. Reinforcement learning algorithms have already been optimized to be query efficient, making them an ideal starting point when designing black-box adversarial attacks. We show the success of our reinforcement learning inspired black-box adversarial attack (RIBA) in generating adversarial perturbations using only a small number of queries to the target model, by comparing it to state of the art attacks on different models on the Cifar10 and ImageNet data sets. RIBA takes $25.4\%$ fewer median queries to generate attacked images against a ResNet-18 on Cifar10 and $22.5\%$ fewer median queries to fool a Vit-B/16 model on ImageNet. Additionally, we demonstrate that RIBA can match the performance of white-box attacks on an adversarially trained model.
Problem

Research questions and friction points this paper is trying to address.

neural networks
adversarial attacks
black-box threat model
Innovation

Methods, ideas, or system contributions that make the work stand out.

Reinforcement Learning
Black-box Adversarial Attacks
Query Efficiency
🔎 Similar Papers
F
Florian Krone
Institute for AI Safety and Security, German Aerospace Center (DLR), Sankt Augustin, Germany
E
Elena Hoemann
Institute for AI Safety and Security, German Aerospace Center (DLR), Sankt Augustin, Germany
S
Sven Hallerbach
Institute for AI Safety and Security, German Aerospace Center (DLR), Sankt Augustin, Germany