Skip to main navigation Skip to search Skip to main content

GenGradAttack: Efficient and Robust Targeted Adversarial Attacks Using Genetic Algorithms and Gradient-Based Fine-Tuning

Research output: Chapter in Book/Report/Conference proceedingConference Contribution (Conference Proceeding)

4 Citations (Scopus)
296 Downloads (Pure)

Abstract

Adversarial attacks pose a critical threat to the reliability of machine learning models, potentially undermining trust in practical applications. As machine learning models find deployment in vital domains like autonomous vehicles, healthcare, and finance, they become susceptible to adversarial examples—crafted inputs that induce erroneous high-confidence predictions. These attacks fall into two main categories: white-box, with full knowledge of model architecture, and black-box, with limited or no access to internal details. This paper introduces a novel approach for targeted adversarial attacks in black-box scenarios. By combining genetic algorithms and gradient-based fine-tuning, our method efficiently explores input space for perturbations without requiring access to internal model details. Subsequently, gradient-based fine-tuning optimizes these perturbations, aligning them with the target model’s decision boundary. This dual strategy aims to evolve perturbations that effectively mislead target models while minimizing queries, ensuring stealthy attacks. Results demonstrate the efficacy of GenGradAttack, achieving a remarkable 95.06% Adversarial Success Rate (ASR) on MNIST with a median query count of 556. In contrast, conventional GenAttack achieved 100% ASR but required significantly more queries. When applied to InceptionV3 and Ens4AdvInceptionV3 on ImageNet, GenGradAttack outperformed GenAttack with 100% and 96% ASR, respectively, and fewer median queries. These results highlight the efficiency and effectiveness of our approach in generating adversarial examples with reduced query counts, advancing our understanding of adversarial vulnerabilities in practical contexts.
Original languageEnglish
Title of host publicationProceedings of the 16th International Conference on Agents and Artificial Intelligence
Subtitle of host publicationICAART
EditorsAna Paula Rocha, Luc Steels, Jaap van den Herik
PublisherSciTePress
Pages202-209
Number of pages8
Volume3
ISBN (Electronic)9789897586804
DOIs
Publication statusPublished - 26 Feb 2024
EventICAART2024 : 16th International Conference on Agents and Artificial Intelligence - Italy, Rome, Italy
Duration: 24 Feb 202426 Feb 2024
Conference number: 16
https://icaart.scitevents.org/Home.aspx
https://portal.insticc.org/SubmissionDeadlines/63e42b755652b110e22e62a4
https://icaart.scitevents.org/?y=2024

Publication series

NameICAART - International Conference on Agents and Artificial Intelligence
PublisherSciTePress
ISSN (Print)2184-3589
ISSN (Electronic)2184-433X

Conference

ConferenceICAART2024
Abbreviated titleICAART2024
Country/TerritoryItaly
CityRome
Period24/02/2426/02/24
Internet address

Bibliographical note

Publisher Copyright:
© 2024 by SCITEPRESS - Science and Technology Publications, Lda.

Keywords

  • Adversarial Machine Learning
  • Privacy Preservation
  • Image Classification

Fingerprint

Dive into the research topics of 'GenGradAttack: Efficient and Robust Targeted Adversarial Attacks Using Genetic Algorithms and Gradient-Based Fine-Tuning'. Together they form a unique fingerprint.

Cite this