Projects per year
Abstract
Adversarial attacks pose a critical threat to the reliability of machine learning models, potentially undermining trust in practical applications. As machine learning models find deployment in vital domains like autonomous vehicles, healthcare, and finance, they become susceptible to adversarial examples—crafted inputs that induce erroneous high-confidence predictions. These attacks fall into two main categories: white-box, with full knowledge of model architecture, and black-box, with limited or no access to internal details. This paper introduces a novel approach for targeted adversarial attacks in black-box scenarios. By combining genetic algorithms and gradient-based fine-tuning, our method efficiently explores input space for perturbations without requiring access to internal model details. Subsequently, gradient-based fine-tuning optimizes these perturbations, aligning them with the target model’s decision boundary. This dual strategy aims to evolve perturbations that effectively mislead target models while minimizing queries, ensuring stealthy attacks. Results demonstrate the efficacy of GenGradAttack, achieving a remarkable 95.06% Adversarial Success Rate (ASR) on MNIST with a median query count of 556. In contrast, conventional GenAttack achieved 100% ASR but required significantly more queries. When applied to InceptionV3 and Ens4AdvInceptionV3 on ImageNet, GenGradAttack outperformed GenAttack with 100% and 96% ASR, respectively, and fewer median queries. These results highlight the efficiency and effectiveness of our approach in generating adversarial examples with reduced query counts, advancing our understanding of adversarial vulnerabilities in practical contexts.
| Original language | English |
|---|---|
| Title of host publication | Proceedings of the 16th International Conference on Agents and Artificial Intelligence |
| Subtitle of host publication | ICAART |
| Editors | Ana Paula Rocha, Luc Steels, Jaap van den Herik |
| Publisher | SciTePress |
| Pages | 202-209 |
| Number of pages | 8 |
| Volume | 3 |
| ISBN (Electronic) | 9789897586804 |
| DOIs | |
| Publication status | Published - 26 Feb 2024 |
| Event | ICAART2024 : 16th International Conference on Agents and Artificial Intelligence - Italy, Rome, Italy Duration: 24 Feb 2024 → 26 Feb 2024 Conference number: 16 https://icaart.scitevents.org/Home.aspx https://portal.insticc.org/SubmissionDeadlines/63e42b755652b110e22e62a4 https://icaart.scitevents.org/?y=2024 |
Publication series
| Name | ICAART - International Conference on Agents and Artificial Intelligence |
|---|---|
| Publisher | SciTePress |
| ISSN (Print) | 2184-3589 |
| ISSN (Electronic) | 2184-433X |
Conference
| Conference | ICAART2024 |
|---|---|
| Abbreviated title | ICAART2024 |
| Country/Territory | Italy |
| City | Rome |
| Period | 24/02/24 → 26/02/24 |
| Internet address |
Bibliographical note
Publisher Copyright:© 2024 by SCITEPRESS - Science and Technology Publications, Lda.
Keywords
- Adversarial Machine Learning
- Privacy Preservation
- Image Classification
Fingerprint
Dive into the research topics of 'GenGradAttack: Efficient and Robust Targeted Adversarial Attacks Using Genetic Algorithms and Gradient-Based Fine-Tuning'. Together they form a unique fingerprint.-
ELABORATOR
Oikonomou, G. (Principal Investigator), Piechocki, R. J. (Co-Investigator), Tryfonas, T. (Co-Investigator), Pope, J. (Co-Investigator) & Erdol, H. (Researcher)
1/06/23 → 30/11/26
Project: Research, Parent
-
CHARIOT: Countering HArms caused by Ransomware in the Internet Of Things
Oikonomou, G. (Principal Investigator), Pope, J. (Co-Investigator), Huang, Y. (Researcher) & Li, H. (Researcher)
1/09/23 → 31/08/26
Project: Research
Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver