genetic algorithm attack

Designs and implements adversarial attack systems that use genetic/evolutionary algorithms to generate input perturbations causing a target model to misclassify, including encoding candidate solutions, defining fitness functions from model outputs (e.g., logits or labels), and applying selection, crossover, and mutation operators. These methods are built to operate with only black-box access to the model—estimating fitness from returned scores or labels—and to optimize attacks toward reducing the model's classification accuracy.

geneticalgorithmattack

Recent Skill Trend

Momentum and market value over time
Trending
Score
No comparison yet
-0.19
Oct 01, 2026Oct 01, 2026
Career
Value
No comparison yet
$200K/year
Oct 01, 2026Oct 01, 2026

Must-Read Papers

Most classic and influential ideas
View more

Adversarial attacks to image classification systems using evolutionary algorithms

Jul 17, 2025
SN
Sergio Nesmachnow
🏛️ Universidad de la República | ITIS | Universidad de Málaga

To address the vulnerability of image classification models to adversarial attacks, this paper proposes a novel adversarial example generation method that integrates evolutionary algorithms (EAs) with generative adversarial networks (GANs): EA efficiently searches for transferable, high-success-rate adversarial perturbations within the GAN’s latent space. By operating in the semantic latent space rather than pixel space, the approach avoids the instability inherent in pixel-level optimization, thereby significantly improving attack robustness and generalization against complex images. Experiments on MNIST and CIFAR-10 demonstrate attack success rates of 35% and 75%, respectively—surpassing state-of-the-art gradient-based and random-search methods. The core contribution is the first systematic incorporation of EAs into GAN latent-space adversarial optimization, effectively balancing adversarial efficacy with generated sample quality. This establishes a new paradigm for efficient, black-box adversarial evaluation.

Exploring latent space of GANs for effective adversarial vector discoveryGenerating adversarial attacks on image classifiers using evolutionary algorithmsImproving attack success rates on diverse datasets like digits and objects

Existing global optimization benchmarks predominantly rely on low-dimensional, outdated analytical functions that fail to capture the complexities of high-dimensional black-box optimization encountered in modern machine learning. This work introduces, for the first time, a systematic formulation of black-box adversarial attacks as a large-scale, high-dimensional global optimization benchmark. The proposed framework enables comprehensive evaluation of diverse evolutionary algorithms and metaheuristic methods under realistic conditions. By bridging the gap between theoretical optimization and practical machine learning challenges, this study not only enhances the real-world relevance of optimization problems but also fosters deeper integration between optimization algorithm design and the demands of contemporary machine learning applications, thereby establishing a more representative and rigorous evaluation platform for future research.

benchmarkingblack-box adversarial attacksevolutionary algorithms

Natural language classifiers are vulnerable to semantics-preserving adversarial attacks in black-box settings, yet existing approaches suffer from limited efficiency and effectiveness. This work proposes GAversary, a novel method that, for the first time, integrates GloVe word embeddings into the mutation operator of a genetic algorithm to generate highly deceptive adversarial examples that maintain semantic similarity—requiring access only to the model’s logit outputs. Evaluated across multiple benchmark datasets, GAversary drastically reduces the target model’s accuracy from 76.8% to 5.8%, significantly outperforming state-of-the-art black-box attack methods such as BAE and A2T in terms of attack success rate.

adversarial textblack-box attacksnatural language classifiers

Protecting Classifiers From Attacks. A Bayesian Approach

Apr 18, 2020
VG
Víctor Gallego
🏛️ Komorebi AI Technologies | CUNEF Universidad | Institute of Mathematical Sciences | CNR-IMATI

To address the vulnerability of classifiers to feature-manipulation attacks—such as those in security-critical applications like malware detection and fraud identification—this paper proposes a Bayesian adversarial robustness framework that dispenses with the common-knowledge assumption. Methodologically, it introduces adversarial risk analysis into classifier defense for the first time, establishing a Bayesian modeling paradigm that requires no prior knowledge of attacker behavior. It further designs an inverse sampling scheme based on Approximate Bayesian Computation (ABC) and integrates attack simulation into the training phase, enabling scalable robust learning. The approach is compatible with large-scale differentiable models and preserves high classification accuracy while significantly improving robustness against both white-box and black-box attacks. Experimental results demonstrate superior defensive performance over mainstream adversarial training baselines.

Addressing uncertainty about attacker behavior using Bayesian methodsProtecting classifiers from adversarial attacks in various domainsRobustifying classification algorithms against malicious perturbations

When Vision Fails: Text Attacks Against ViT and OCR

Jun 12, 2023
NB
Nicholas Boucher
🏛️ University of Cambridge | University of Oxford | University of Edinburgh | University of Toronto | Vector Institute

Existing OCR systems and vision-language models (e.g., ViT) exhibit high vulnerability to visual adversarial perturbations induced by Unicode combining diacritical marks—perturbations that remain imperceptible to humans yet cause severe misrecognition under black-box attacks. Method: This work introduces the first Unicode-combining-character-based text-to-vision adversarial attack paradigm. It models cross-platform text rendering behavior and devises a genetic-algorithm-driven black-box framework for generating adversarial perturbations—requiring neither model gradients nor training data. Contribution/Results: Our method successfully compromises production-grade OCR and multimodal models from Facebook, Microsoft, IBM, and Google. 98.7% of generated adversarial samples retain full human readability, while exhibiting strong transferability and practicality. The results expose a critical blind spot in multimodal security: the text rendering layer, which has been largely overlooked in prior adversarial robustness research.

Attacking text-based ML models using Unicode adversarial examplesBreaking OCR defenses through visual adversarial text perturbationsDemonstrating vulnerabilities in production models from major tech companies

Latest Papers

What's happening recently
View more

This work addresses the limitations of traditional evolutionary attacks, where discrete crossover operations often disrupt the structural integrity of adversarial perturbations, leading to inefficient search and poor transferability. To overcome this, the authors propose MoCo-EA, a novel method that introduces Bézier curves into evolutionary attacks for the first time, constructing continuous paths between parent perturbations and optimizing intermediate points along these trajectories. This approach reveals a pattern connectivity property of adversarial examples: intermediate perturbations exhibit stronger transferability than endpoint ones. By integrating a Bézier-based continuous crossover operator with gradient-free evolutionary search, MoCo-EA substantially reduces query counts and convergence time while simultaneously improving attack success rates and cross-model transferability.

adversarial perturbationscrossover inefficiencyevolutionary attacks

Existing machine learning defense mechanisms primarily focus on the attacks themselves and struggle to identify the attackers, thereby limiting the effectiveness of system-level mitigation strategies. This work proposes the first domain-agnostic framework that shifts the defensive perspective from the attack to the attacker by modeling adversarial behavior and leveraging probabilistic inference to infer attacker characteristics without prior knowledge. Theoretical analysis shows that while attackers cannot be uniquely identified, their attributes can be characterized probabilistically. The framework is applicable across diverse learning models and attack scenarios. Experimental results demonstrate that it not only enhances the precision of exogenous mitigation strategies but also improves the performance of endogenous defense mechanisms such as adversarial regularization.

adversarial defenseadversary identificationattacker characteristics

This work investigates the problem of best-arm identification in multi-armed bandits under unknown reward mechanisms, which may be either stochastic or adversarial. We first establish that it is impossible to achieve optimality simultaneously in both stochastic and adversarial environments, and we characterize a fundamental lower bound on the error probability in stochastic settings under the constraint of adversarial robustness. Building on this insight, we propose the first parameter-free algorithm that adaptively operates without prior knowledge of the reward nature: in stochastic environments, its error probability matches the theoretical lower bound up to a logarithmic factor, while maintaining robustness in adversarial environments. By integrating techniques from best-arm identification theory, minimax lower bound analysis, and parameter-free online learning, our approach achieves breakthroughs both theoretically and empirically.

adversarial rewardsbest-arm identificationmulti-armed bandits

This work addresses the inefficiency of traditional genetic algorithms in solving optimization problems due to their reliance on random mutation and recombination, which lack goal-directedness. The authors formulate the problem through the lens of query complexity and propose objective-guided mutation and recombination operators informed by the optimization target. Leveraging reinforcement learning and formal language theory, they analyze the theoretical properties of these operators. For the first time, the study mathematically characterizes the mechanism of goal-directed genetic operators and demonstrates the necessity of population diversity for certain classes of optimization problems. A general model of genetic algorithms is established, enabling the design of a tight algorithm for a specific problem class, and proving that the synergy among generation, mutation, and recombination is essential for efficient optimization.

diversitygenetic algorithmsmutation operators

Hot Scholars

FR

Fabio Roli

Professor, University of Genova and Cagliari, Italy
Pattern recognitionmachine learningcomputer visioncomputer security
AD

Ambra Demontis

Assistant Professor at University of Cagliari
machine learningadversarial machine learningimage recognition
MP

Maura Pintor

University of Cagliari
Machine LearningAdversarial Machine LearningComputer Security
HB

Hubert Baniecki

PhD student, University of Warsaw
machine learninginterpretabilityexplainable AI
PB

Przemyslaw Biecek

Warsaw University of Technology
Explainable Artificial Intelligence