• Home
  • Search
  • AS-ES: Sparse Black-box Adversarial Attack by Active Subspace Evolution Strategy
  • https://doi.org/10.65286/icic.v21i2.46248Copy DOI Icon

AS-ES: Sparse Black-box Adversarial Attack by Active Subspace Evolution Strategy

  • Jan 1, 2025
  • Duan Jinling
Show More
  • Abstract
  • Literature Map
  • Similar Papers
Abstract

In adversarial attacks, most existing methods adopt global attack methods, which attack by changing all image pixels, but this is not realistic. On the contrary, sparse attacks indicate that only perturbing local regions of the input image can deceive DNN models into making incorrect predictions. However, this method requires a large number of queries to generate adversarial examples, and the key issues it faces are locating the perturbation area and optimizing the magnitude of the perturbation. Currently, generating high-quality adversarial examples and improving query efficiency in restricted environments is a challenge for black-box attacks. In this paper, we propose a sparse black-box attack method based on the Active Subspace Evolution Strategy AS-ES , which locates the active subspace of the input image through the multi-arm bandit method, and uses the Covariance Matrix Adaptive Evolution Strategy algorithm for perturbation search in the low-dimensional subspace. We model this problem as a bi-level optimization problem, optimizing both the perturbation position and magnitude to generate high-quality adversarial examples while achieving efficient attacks. We conducted extensive experiments on multiple datasets and verified that the AS-ES method generates adversarial examples with higher quality and query efficiency than existing state-of-the-art attack methods.

Similar Papers
  • PDF
  • Research Article
  • Citations26

On the Effectiveness of Adversarial Training in Defending against Adversarial Example Attacks for Image Classification

  • Nov 14, 2020
  • Applied Sciences
  • Sanglee Park +1
  • Research Article
  • Citations52

Adversarial Attack and Defense on Deep Learning for Air Transportation Communication Jamming

  • Jan 01, 2024
  • IEEE Transactions on Intelligent Transportation Systems
  • Mingqian Liu +4
  • Book Chapter

GF-Attack: A Strategy to Improve the Performance of Adversarial Example

  • Jan 01, 2020
  • Jintao Zhang +5
  • Research Article
  • Citations3

Explanation-Guided Adversarial Example Attacks

  • Mar 26, 2024
  • Big Data Research
  • Anli Yan +4
  • Research Article

Towards Patch-Based Noise Compression for Adversarial Attack Against Transformer-Based Visual Tracking

  • Jan 01, 2026
  • IEEE Transactions on Information Forensics and Security
  • Peng Gao +6
  • PDF
  • Research Article
  • Citations8

A CMA-ES-Based Adversarial Attack on Black-Box Deep Neural Networks

  • Jan 01, 2019
  • IEEE Access
  • Xiaohui Kuang +5
  • Research Article
  • Citations7

SAR-PATT: A Physical Adversarial Attack for SAR Image Automatic Target Recognition

  • Dec 25, 2024
  • Remote Sensing
  • Binyan Luo +6
  • Research Article
  • Citations2

General Sparse Adversarial Attack Method for SAR Images Based on Keypoints

  • Oct 01, 2025
  • IEEE Transactions on Aerospace and Electronic Systems
  • Fei Gao +5
  • Conference Article
  • Citations7

From Image to Code

  • Apr 23, 2020
  • Shangyu Gu +2
  • Conference Article

Adversarial Image Detection for Vision Transformers via Attention Map

  • Aug 11, 2025
  • S Park +2
  • Research Article

KEM-Attack: knowledge-enhanced metaheuristic framework for hard-label textual adversarial attacks

  • Apr 22, 2026
  • PeerJ Computer Science
  • Hong Zhao +1
  • Conference Article
  • Citations4

RamBoAttack: A Robust and Query Efficient Deep Neural Network Decision Exploit

  • Jan 01, 2022
  • Viet Quoc Vo +2
  • PDF
  • Research Article
  • Citations34

Adversarial Attack for SAR Target Recognition Based on UNet-Generative Adversarial Network

  • Oct 29, 2021
  • Remote Sensing
  • Chuan Du +1
  • Book Chapter

Query-Efficient Black-Box Adversarial Attack with Random Pattern Noises

  • Jan 01, 2022
  • Makoto Yuito +2
  • Research Article
  • Citations70

An adversarial attack on DNN-based black-box object detectors

  • Mar 29, 2020
  • Journal of Network and Computer Applications
  • Yajie Wang +4
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.