• Home
  • Search
  • Dynamic Routing and Knowledge Re-Learning for Data-Free Black-Box Attack.
  • Cite Icon3
  • https://doi.org/10.1109/tpami.2024.3469952Copy DOI Icon

Dynamic Routing and Knowledge Re-Learning for Data-Free Black-Box Attack.

  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

Deep learning models have emerged as strong and efficient tools that can be applied to a broad spectrum of complex learning problems and many real-world applications. However, more and more works show that deep models are vulnerable to adversarial examples. Compared to vanilla attack settings, this paper advocates a more practical setting of data-free black-box attack, for which the attackers can completely not access the structures and parameters of the target model, as well as the intermediate features and any training data associated with the model. To tackle this task, previous methods generate transferable adversarial examples from a transparent substitute model to the target model. However, we found that these works have the limitations of taking static substitute model structure for different targets, only using hard synthesized examples once, and still relying on data statistics of the target model. This may potentially harm the performance of attacking the target model. To this end, we propose a novel Dynamic Routing and Knowledge Re-Learning framework (DraKe) to effectively learn a dynamic substitute model from the target model. Specifically, given synthesized training samples, a dynamic substitute structure learning strategy is proposed to adaptively generate optimal substitute model structure via a policy network according to different target models and tasks. To facilitate the substitute training, we present a graph-based structure information learning to capture the structural knowledge learned from the target model. For the inherent limitation that online data generation can only be learned once, a dynamic knowledge re-learning strategy is proposed to adjust the weights of optimization objectives and re-learn hard samples. Extensive experiments on four public image classification datasets and one face recognition benchmark are conducted to evaluate the efficacy of our Drake. We can obtain significant improvement compared with state-of-the-art competitors. More importantly, our DraKe consistently achieves attack superiority for different target models (e.g., residual networks, and vision transformers), showing great potential for complex real-world applications.

Similar Papers
  • Research Article
  • Citations12

Transferable adversarial examples can efficiently fool topic models

  • May 02, 2022
  • Computers & Security
  • Zhen Wang +4
  • Conference Article
  • Citations3

How Robust is Your Automatic Diagnosis Model?

  • Nov 01, 2019
  • Ke Wang +3
  • Research Article
  • Citations5

Crafting Transferable Adversarial Examples Against Face Recognition via Gradient Eroding

  • Jan 01, 2024
  • IEEE Transactions on Artificial Intelligence
  • Huipeng Zhou +6
  • Research Article
  • Citations152

Assessing the Threat of Adversarial Examples on Deep Neural Networks for Remote Sensing Scene Classification: Attacks and Defenses

  • Jun 16, 2020
  • IEEE Transactions on Geoscience and Remote Sensing
  • Yonghao Xu +2
  • Research Article
  • Citations11

Efficient Generation of Targeted and Transferable Adversarial Examples for Vision-Language Models via Diffusion Models

  • Jan 01, 2025
  • IEEE Transactions on Information Forensics and Security
  • Qi Guo +4
  • PDF
  • Research Article
  • Citations3

Clustering Approach for Detecting Multiple Types of Adversarial Examples

  • May 18, 2022
  • Sensors (Basel, Switzerland)
  • Seok-Hwan Choi +3
  • Book Chapter
  • Citations4

On the Salience of Adversarial Examples

  • Jan 01, 2019
  • Amanda Fernandez
  • Research Article
  • Citations19

FE-DaST: Fast and effective data-free substitute training for black-box adversarial attacks

  • Nov 20, 2021
  • Computers & Security
  • Mengran Yu +1
  • Research Article

Robust Token Gradient and Frequency-Aware Transferable Adversarial Attacks on Vision Transformers

  • Jan 01, 2025
  • IEEE Transactions on Information Forensics and Security
  • Cong Hu +3
  • Research Article

DRHA-SR: Dual-Region Hierarchical Attack for Stealthy Black-Box Adversarial Examples in Remote Sensing

  • Jan 01, 2025
  • IEEE Journal of Selected Topics in Applied Earth Observations and Remote Sensing
  • Z L Zhang +2
  • Research Article

On the Adversarial Transferability of Generalized "Skip Connections".

  • Feb 18, 2026
  • IEEE transactions on pattern analysis and machine intelligence
  • Yisen Wang +5
  • Conference Article
  • Citations7

From Image to Code

  • Apr 23, 2020
  • Shangyu Gu +2
  • Conference Article
  • Citations35

Parallel Rectangle Flip Attack: A Query-based Black-box Attack against Object Detection

  • Oct 01, 2021
  • Siyuan Liang +4
  • Book Chapter
  • Citations8

GM-Attack: Improving the Transferability of Adversarial Attacks

  • Jan 01, 2022
  • Jinbang Hong +5
  • Research Article
  • Citations134

Self-Attention Context Network: Addressing the Threat of Adversarial Attacks for Hyperspectral Image Classification.

  • Jan 01, 2021
  • IEEE Transactions on Image Processing
  • Yonghao Xu +2
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.