Hybrid Batch Attacks: Finding Black-box Adversarial Examples with Limited Queries

We study adversarial examples in a black-box setting where the adversary only\nhas API access to the target model and each query is expensive. Prior work on\nblack-box adversarial examples follows one of two main strategies: (1) transfer\nattacks use white-box attacks on local models to find candidate adversarial\nexamples that transfer to the target model, and (2) optimization-based attacks\nuse queries to the target model and apply optimization techniques to search for\nadversarial examples. We propose hybrid attacks that combine both strategies,\nusing candidate adversarial examples from local models as starting points for\noptimization-based attacks and using labels learned in optimization-based\nattacks to tune local models for finding transfer candidates. We empirically\ndemonstrate on the MNIST, CIFAR10, and ImageNet datasets that our hybrid attack\nstrategy reduces cost and improves success rates. We also introduce a seed\nprioritization strategy which enables attackers to focus their resources on the\nmost promising seeds. Combining hybrid attacks with our seed prioritization\nstrategy enables batch attacks that can reliably find adversarial examples with\nonly a handful of queries.\n

Paper

References (45)

Scroll for more · 33 remaining

Similar papers

© 2026 NYSGPT2525 LLC