Narodytska, Nina, and Shiva Kasiviswanathan. "
Simple Black-Box Adversarial Perturbations for Deep Networks.
" (2016).
Transfer-based attacks
不依赖模型结构和网络权重,但是需要大概知道网络的结构
论文:
Papernot, Nicolas, Patrick McDaniel, and Ian Goodfellow. "
Transferability in Machine Learning: from Phenomena to Black-Box Attacks using Adversarial Samples.
" (2016).
Papernot, Nicolas, et al. "
Practical black-box attacks against machine learning.
" Proceedings of the 2017 ACM on Asia conference on computer and communications security. 2017.
Decision-based attacks
只需知道输出标签,但是查询次数比较多,上万次甚至数十万次
论文:
Brendel, Wieland, Jonas Rauber, and Matthias Bethge. "
Decision-Based Adversarial Attacks: Reliable Attacks Against Black-Box Machine Learning Models.
" International Conference on Learning Representations. 2018.