arXiv · 2210.16371
Distributed Black-box Attack: Do Not Overestimate Black-box Attacks
Abstract
As cloud computing becomes pervasive, deep learning models are deployed on cloud servers and then provided as APIs to end users. However, black-box adversarial attacks can fool image classification models without access to model structure and weights. Recent studies have reported attack success rates of over 95% with fewer than 1,000 queries. Then the question arises: whether black-box attacks have become a real threat against cloud APIs? To shed some light on this, our research indicates that black-box attacks are not as effective against cloud APIs as proposed in research papers due to several common mistakes that overestimate the efficiency of black-box attacks. To avoid similar mistakes, we conduct black-box attacks directly on cloud APIs rather than local models.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Han Wu, Sareh Rowlands, Johan Wahlstrom. 2022-10-28. Distributed Black-box Attack: Do Not Overestimate Black-box Attacks. https://arxiv.org/abs/2210.16371
Cite the original work for its findings. Save a collection to share your selection of sources.