Reinforcement Learning Platform for Adversarial Black-box Attacks with Custom Distortion Filters

📅 2025-01-23
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
To address the challenges of robustness evaluation and low attack efficiency for image recognition models under black-box settings, this paper proposes a deep reinforcement learning–based adversarial attack platform. Methodologically, it introduces a dual-action mechanism—adaptive exploration of sensitive regions and dynamic removal of ineffective perturbations—supporting both untargeted and targeted attacks; incorporates a customizable distortion filter to constrain perturbation norms; and integrates robustness quantification and adversarial retraining modules. Experiments on CIFAR-10 and ImageNet demonstrate that the platform reduces average query counts significantly compared to state-of-the-art methods. Furthermore, models adversarially trained using samples generated by this platform achieve 12.6%–18.3% improvements in robustness against white-box (e.g., PGD) and black-box (e.g., AutoAttack) adversaries.

Technology Category

Computer Vision: Adversarial Attacks & RobustnessMachine Learning: Adversarial Learning & RobustnessSearch and Optimization: Adversarial Search

Application Category

User Modeling, Personalization and Recommendation: Attacks and countermeasures in recommendation systemsSearch and Retrieval-Augmented AI: Web learning to rank, online learning, and counterfactual learning for rankingEconomics, Online Markets and Human Computation: Economics and fairness of platforms and recommendation systems
📝 Abstract
We present a Reinforcement Learning Platform for Adversarial Black-box untargeted and targeted attacks, RLAB, that allows users to select from various distortion filters to create adversarial examples. The platform uses a Reinforcement Learning agent to add minimum distortion to input images while still causing misclassification by the target model. The agent uses a novel dual-action method to explore the input image at each step to identify sensitive regions for adding distortions while removing noises that have less impact on the target model. This dual action leads to faster and more efficient convergence of the attack. The platform can also be used to measure the robustness of image classification models against specific distortion types. Also, retraining the model with adversarial samples significantly improved robustness when evaluated on benchmark datasets. The proposed platform outperforms state-of-the-art methods in terms of the average number of queries required to cause misclassification. This advances trustworthiness with a positive social impact.
Problem

Research questions and friction points this paper is trying to address.

Adversarial Examples
Reinforcement Learning
Robustness in Image Recognition
Innovation

Methods, ideas, or system contributions that make the work stand out.

Reinforcement Learning
Adversarial Perturbations
Robustness Assessment