Skip to main content

Table 1 The performance comparison of black-box adversarial attack on the CIFAR-10 dataset, with the perturbation \(\epsilon =8\) and \(\epsilon =16\)

From: DTA: distribution transform-based attack for query-limited scenario

\(\epsilon\)

Target Model

Methods

Attack success rate (%)

Avg. query number

Med. query number

100

200

300

400

500

100

200

300

400

500

100

200

300

400

500

8

VGG-16

Sign-OPT

–

0.54

3.54

2.56

3.74

–

148.8

256.94

257.04

310.17

–

144

264

255.5

264

Bandits

18.26

18.92

20.42

21.62

25.48

26.66

39.56

62.83

73.28

100.44

14

18

26

28

38

Rays

7.45

17.34

25.24

32.00

37.97

65.71

122.73

161.38

208.26

233.01

61.5

126

161

205

215

Tangent

3.04

3.62

3.91

4.44

4.95

21.01

48.84

48.84

87.31

141.95

28

28

28

28

28

TA

3.70

3.93

4.14

4.37

5.18

16.46

27.28

20.51

37.58

45.75

6

5

5

5

5

CGBA

2.11

3.33

5.49

6.62

7.64

71.91

99.68

153.87

190.72

230.89

89

93

149

159

216

Ours

69.35

71.23

72.36

73.00

73.57

5.76

9.45

12.40

15.02

19.02

3

5

4

5

5

MobileNetv2

Sign-OPT

–

0.11

6.77

5.59

8.71

–

152.00

251.86

256.60

295.20

–

152

255

254

273

Bandits

36.53

45.32

47.38

51.62

51.85

24.84

43.54

66.49

51.62

103.84

14

18

30

40

50

Rays

12.11

30.38

43.72

56.84

59.91

68.48

123.19

168.73

207.71

235.22

66

124.5

170

208.5

224

Tangent

7.15

8.51

8.22

9.42

10.53

20.93

47.10

48.75

81.57

129.79

28

28

28

28

28

TA

8.24

8.42

8.54

8.87

8.97

12.48

21.30

21.46

22.98

27.62

5

5

5

5

5

CGBA

2.71

4.26

6.55

7.95

8.95

63.31

94.16

148.26

182.03

212.24

45

91

147

152

211

Ours

78.01

79.2

80.48

81.31

81.53

4.45

6.91

9.93

12.46

14.55

3

3

4

4

4

ShuffleNetv2

Sign-OPT

–

0.22

3.99

5.00

5.27

–

186.00

260.03

265.8

288.69

–

186

262

261

272

Bandits

26.91

36.80

39.80

43.97

49.72

30.66

48.70

75.78

103.57

113.88

20

26

46

52

58

Rays

12.16

26.93

37.19

48.57

55.6

67.88

121.65

153.27

197.38

224.49

66.5

124

148

190

194.00

Tangent

3.83

4.71

4.54

5.12

5.80

19.58

49.85

48.75

89.25

140.08

28

28

28

28

28

TA

5.42

6.42

6.69

7.34

8.25

17.98

15.98

39.62

41.53

46.82

5

5

6

6

5

CGBA

3.34

5.12

8.14

9.92

11.44

73.60

100.10

157.20

188.55

228.53

89

93

150

156

215

Ours

75.08

77.00

78.15

78.72

79.05

4.36

7.24

10.29

12.09

15.27

4

4

4

5

5

16

VGG-16

Sign-OPT

–

1.07

9.33

9.18

11.98

–

151.60

259.14

267.55

286.43

–

151

266

268.5

266.5

Bandits

54.14

58.86

66.27

63.96

66.52

27.14

39.71

45.45

56.68

63.47

18

24

22

24

28

Rays

21.17

43.12

60.66

70.90

80.32

65.70

118.04

161.62

187.88

211.81

65

118.5

162

184

196

Tangent

14.72

18.45

18.04

20.92

22.92

22.05

50.09

50.93

92.62

134.20

28

28

28

28

28

TA

16.63

17.26

18.51

20.27

22.74

14.84

18.32

19.27

27.90

33.79

5

5

5

5

5

CGBA

4.10

6.67

10.07

12.21

13.85

58.28

90.84

145.05

183.00

216.49

41

89

144

151

211

Ours

75.32

77.95

79.11

79.96

80.59

4.53

7.93

11.86

13.43

15.43

1

1

1

1

1

MobileNetv2

Sign-OPT

–

1.19

16.99

20.44

25.59

–

178.09

250.44

262.80

298.54

–

174

255

264

268

Bandits

74.02

79.16

85.55

84.58

87.10

23.04

29.08

34.68

43.22

48.94

16

16

16

18

16

Rays

34.64

60.60

74.87

85.35

89.71

69.67

108.94

133.98

152.75

179.82

69

104

117

132

149

Tangent

27.57

32.84

33.29

36.68

39.01

21.36

47.12

50.15

77.49

126.86

28

28

28

28

28

TA

31.92

33.44

38.63

39.45

42.41

12.60

18.01

22.70

27.31

32.31

5

5

5

5

5

CGBA

7.59

10.06

14.88

16.69

19.43

53.71

77.82

131.22

158.47

200.29

40

44.5

97

143

158

Ours

86.14

88.7

89.66

90.30

91.05

4.26

7.78

9.79

11.93

13.90

1

1

1

1

1

ShuffleNetv2

Sign-OPT

–

0.11

9.70

11.62

15.26

–

183.00

261.43

268.28

309.84

–

183

263

266

275

Bandits

63.19

73.59

74.76

76.68

77.23

26.82

38.57

48.33

57.23

63.78

20

20

24

24

24

Rays

31.79

58.19

74.73

83.37

86.11

63.64

108.71

138.37

156.16

179.90

63

102

129

139

146.5

Tangent

16.28

20.20

20.00

22.68

25.17

21.59

49.42

52.29

90.03

131.56

28

28

28

28

28

TA

23.77

25.80

26.79

28.80

29.48

15.00

25.43

30.14

36.07

42.08

5

5

5.5

5

5

CGBA

6.37

10.05

15.29

18.12

20.81

59.07

87.28

148.99

182.12

218.26

42

87

147

152

212

Ours

82.11

84.91

86.1

87.29

87.82

5.28

8.60

12.02

15.07

17.05

1

1

1

1

1

  1. The bold results are the best
  2. We report the attack success rate (ASR (%)), average query number, and median query number under the max query limited in 100, 200, 300, 400 and 500, respectively