| 注册
首页|期刊导航|信息安全研究|基于显著性检测的黑盒对抗攻击近似决策边界方法

基于显著性检测的黑盒对抗攻击近似决策边界方法

串立雪 陈龙

信息安全研究2026,Vol.12Issue(4):340-347,8.
信息安全研究2026,Vol.12Issue(4):340-347,8.DOI:10.12379/j.issn.2096-1057.2026.04.06

基于显著性检测的黑盒对抗攻击近似决策边界方法

Approximate Decision Boundary Approach for Black-box Adversarial Attacks Based on Saliency Detection

串立雪 1陈龙1

作者信息

  • 1. 重庆邮电大学网络空间安全与信息法学院 重庆 400065
  • 折叠

摘要

Abstract

Decision-based black-box adversarial attacks have become an important research direction in the field of artificial intelligence security.Existing methods primarily approximate the decision boundary through uniform random traversal type search,ignoring the correlation between the semantic structure of the image and the region of interest of the model,and there are problems of blind search direction,insensitive region,and low query efficiency.To this end,this paper proposes a saliency-guided adversarial decision boundary attack(S-ADBA)method,which is designed for black-box image classification systems that only provide hard-label predictions in query budget-constrained scenarios,and guides the perturbation with saliency mask semanticsto act preferentially on key sensitive regions of the image,thereby reducing redundant queries and improving the efficiency of the attack.Experiments on the ImageNet dataset show that S-ADBA outperforms the baseline attack methods on several mainstream models,with the number of queries decreasing by 11.5%,25.3%,3.6%,30.4%,and 8.8%respectively on VGG-19,Inception-V3,EffcientNet-B0,DenseNet161,and ViT-B32 respectively,while maintaining or improving the attack success rate,maintaining good robustness and achieving an effective balance between query efficiency and attack stealth.

关键词

决策边界/显著性检测,黑盒对抗攻击/硬标签/对抗样本

Key words

decision boundary/saliency detection/black-box adversarial attack/hard label/adversarial sample

分类

信息技术与安全科学

引用本文复制引用

串立雪,陈龙..基于显著性检测的黑盒对抗攻击近似决策边界方法[J].信息安全研究,2026,12(4):340-347,8.

信息安全研究

2096-1057

访问量0
|
下载量0
段落导航相关论文