Skip to main content

Table 2 The performance comparison of black-box adversarial attack on the SVHN dataset, with the perturbation \(\epsilon =8\) and \(\epsilon =16\)

From: DTA: distribution transform-based attack for query-limited scenario

\(\epsilon\)

Target Model

Methods

Attack success rate (%)

Avg. query number

Med. query number

100

200

300

400

500

100

200

300

400

500

100

200

300

400

500

8

VGG-16

Sign-OPT

–

–

1.85

2.27

1.30

–

–

257.24

261.00

325.33

–

–

257

253

288

Bandits

11.22

20.71

24.23

26.85

32.19

33.79

60.30

103.77

13.61

145.20

26

40

76

106

104

Rays

9.77

22.72

35.87

45.84

51.50

69.34

126.15

172.37

207.28

234.90

76.5

131

175

205

221

Tangent

1.35

1.51

1.56

1.74

1.88

20.28

50.47

45.73

88.24

139.75

28

28

28

28

28

TA

4.30

4.41

4.63

4.77

5.05

29.93

42.65

48.88

53.91

57.58

19

33.5

18

21

20.5

CGBA

5.21

9.60

13.81

18.22

19.09

78.42

107.65

155.97

189.58

215.50

94

99

154

161

217

Ours

47.62

51.29

53.03

54.44

55.36

6.11

10.96

15.86

20.45

24.66

4

5

5

6

7

MobileNetv2

Sign-OPT

–

–

2.42

1.86

1.44

–

–

256.52

257.56

290.21

–

–

250

257

260

Bandits

10.90

14.71

21.11

25.29

26.26

35.77

72.76

114.28

139.97

173.94

32

52

96

101

138

Rays

5.22

16.75

27.33

36.07

45.31

71.50

138.94

179.41

225.09

255.95

71

140.5

181

232

249

Tangent

0.98

1.11

1.14

1.27

1.32

20.07

48.55

46.87

88.34

116.83

28

28

28

28

28

TA

2.19

2.11

2.77

2.69

3.01

19.38

40.50

37.82

45.42

45.07

5

25.5

16

16

7

CGBA

3.94

7.38

11.04

13.08

14.92

78.50

109.73

160.55

188.97

217.22

94.5

99

155

161

218

Ours

37.66

41.09

43.10

44.53

47.47

6.06

11.29

15.77

20.72

25.80

5

6

7

7

7

ShuffleNetv2

Sign-OPT

–

–

1.89

2.02

1.89

–

–

254.06

248.90

268.45

–

–

257

247

254

Bandits

9.35

14.93

20.84

20.75

27.42

38.09

72.95

110.80

130.09

172.42

30

60

80

110

122

Rays

7.32

18.49

35.10

41.40

47.08

72.32

131.56

175.13

227.31

255.19

74

137

176

234

244.5

Tangent

0.93

0.98

1.13

1.18

1.27

18.82

50.48

43.97

89.16

103.99

11

28

28

28

28

TA

2.62

2.20

2.21

2.49

2.56

21.36

24.48

43.81

62.21

46.00

7

6

23

32.5

16

CGBA

3.97

7.59

12.25

14.92

16.58

78.79

107.34

158.09

192.36

216.83

95

100

156

161

218

Ours

40.09

43.76

45.63

46.78

49.76

5.97

11.05

15.82

20.07

24.70

5

7

8

8

9

16

VGG-16

Sign-OPT

–

–

3.81

5.93

5.63

–

–

257.51

259.55

297.23

–

–

257

261

263

Bandits

28.14

33.51

34.05

41.51

42.11

32.51

50.42

65.74

104.86

130.52

24

32

36

50

62

Rays

23.98

53.68

70.91

81.58

85.13

70.65

116.16

152.35

173.04

194.00

68.5

115

148

165

173

Tangent

4.24

5.32

5.03

6.04

6.61

20.57

52.42

48.75

97.55

148.16

28

28

28

28

28

TA

10.65

12.35

13.16

14.39

15.33

25.55

34.89

53.00

61.44

55.61

12

15

25.5

25.5

14

CGBA

9.29

17.48

26.95

31.91

36.33

77.52

108.66

160.72

194.79

227.29

93

99

155

161

220

Ours

71.61

72.63

74.39

78.41

84.11

10.04

15.87

22.28

27.64

37.28

3

3

4

4

4

MobileNetv2

Sign-OPT

–

–

4.64

4.44

4.32

–

–

261.43

260.54

278.17

–

–

262

260

258

Bandits

22.75

29.23

35.77

35.18

40.33

37.86

60.04

76.75

101.23

126.68

32

36

44

53

66

Rays

13.92

33.65

55.86

68.38

75.63

73.39

125.95

170.54

205.98

233.09

72

131

166

201.5

210.5

Tangent

3.40

3.68

3.96

4.24

4.73

21.15

48.75

54.76

94.45

133.37

28

28

28

28

28

TA

5.38

7.41

6.15

7.32

8.12

22.49

28.70

35.22

45.56

63.19

8

8

13

11

16

CGBA

7.47

13.75

22.74

28.06

31.83

80.14

110.20

168.95

203.78

232.06

94

100

157

216

221

Ours

65.41

68.07

71.90

73.27

78.18

12.64

17.55

21.30

27.79

30.24

4

4

3

3

4

ShuffleNetv2

Sign-OPT

–

0.11

4.41

4.57

5.24

–

197.00

255.91

259.00

308.15

–

197

255.5

254

276.5

Bandits

22.97

28.07

32.26

35.24

38.21

36.35

64.62

84.43

104.09

125.30

30

44

48

54

62

Rays

17.22

44.02

64.49

74.63

80.19

74.07

125.03

174.63

193.11

222.37

76

127

176

180.5

208

Tangent

2.81

3.15

3.20

3.91

4.19

20.93

53.41

51.26

88.87

149.96

28

28

28

28

29

TA

5.68

7.14

8.33

7.45

7.79

29.20

38.74

45.35

47.85

73.89

16.5

17.5

17.5

22

32

CGBA

7.71

14.59

23.36

29.14

32.75

78.06

107.36

160.92

203.51

234.70

94

99

156

215

222

Ours

67.99

72.84

75.74

77.26

78.72

10.68

17.57

19.83

26.07

38.08

4

5

4

4

4

  1. The bold results are the best
  2. We report the attack success rate (ASR (%)), average query number, and median query number under the max query limited in 100, 200, 300, 400 and 500, respectively