Nonlinear Projection Based Gradient Estimation for Query Efficient Blackbox Attacks论文解读

Abstract

Gradient estimation以及vector space projection现在被作为两个独立的主题进行研究。我们希望bridge the gap between the
two by investigating how to efficiently estimate gradient based on a projected low-dimensional space. We first provide lower
and upper bounds for gradient estimation under both linear and nonlinear gradient projections, and outline checkable sufficient conditions under which one is better than the other. Moreover, we analyze the query complexity for the projection-based gradient estimation and present a sufficient condition for query-efficient estimators. Built upon our
theoretic analysis, we propose a novel queryefficient Nonlinear Gradient Projection-based
Boundary Blackbox Attack (NonLinearBA). We conduct extensive experiments on
four datasets: ImageNet, CelebA, CIFAR-10,
and MNIST, and show the superiority of the
proposed methods compared with the stateof-the-art baselines. In particular, we show
that the projection-based boundary blackbox attacks are able to achieve much smaller
magnitude of perturbations with 100% attack success rate based on efficient queries.
Both linear and nonlinear projections demonstrate their advantages under different conditions. We also evaluate NonLinear-BA against
the commercial online API MEGVII Face++,
and demonstrate the high blackbox attack
performance both quantitatively and qualitatively.

1 Introduction

Gradient estimation and vector space projection have
both been extensively studied in machine learning, but
largely for different purposes. Gradient estimation is
used when gradient-based optimization such as backpropagation is employed but the exact gradients are
not directly accessible, for example, in the case of blackbox adversarial attacks (Chen et al., 2020; Li et al.,
2020). Vector space projection, especially gradient projection (or sparsification), on the other hand, has been
used to speedup training, for instance, by reducing the
complexity of communication and/or storage when performing model update in distributed training (Wangni
et al., 2018). In this paper, we aim to bridge the gap
between the two and attempt to answer the following
questions: Can we estimate gradients from a projected
low-dimensional subspace? How do different projections
affect the gradient estimation quality?

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值