Skip to main content

Table 3 The performance comparison of black-box adversarial attack on the ImageNet dataset, with the perturbation \(\epsilon =8\) and \(\epsilon =16\)

From: DTA: distribution transform-based attack for query-limited scenario

\(\epsilon\)

Target Model

Methods

Attack success rate (%)

Avg. query number

Med. query number

100

200

300

400

500

100

200

300

400

500

100

200

300

400

500

8

VGG-16

Sign-OPT

–

–

4.77

4.49

4.77

–

–

261.09

273.72

306.38

–

–

260.5

264

272.5

Bandits

21.35

26.63

30.28

45.84

48.28

26.92

52.78

87.87

122.02

140.74

12

26

56

75

84

Rays

13.18

24.72

35.53

45.58

48.25

70.41

114.20

159.00

202.66

235.97

72

110

152

199

229

Tangent

4.63

4.91

5.47

4.77

5.61

19.56

39.27

34.04

69.47

27.10

11

11

11

11

11

TA

23.70

26.23

27.35

28.61

28.47

21.04

31.01

40.86

56.43

53.12

11

16

18

18

18

CGBA

5.89

9.68

12.90

18.23

22.16

75.98

103.77

145.72

205.66

246.06

93.5

98

155

191.5

232

Ours

24.86

28.37

33.06

39.79

44.21

9.98

28.01

25.06

43.20

44.46

2

3

3

4

4

MobileNetv2

Sign-OPT

–

–

6.34

6.90

7.61

–

–

265.78

269.82

279.50

–

–

264

269

267.5

Bandits

28.17

28.38

36.49

33.85

39.68

23.83

51.22

85.94

112.80

131.95

6

17

42

64

67

Rays

20.14

29.44

33.86

45.15

61.35

65.73

95.56

150.64

194.50

220.72

60

83

134

196

224

Tangent

5.92

6.20

7.32

5.49

6.76

14.35

23.00

18.22

26.93

42.14

11

11

11

11

11

TA

22.54

24.37

24.93

26.48

27.46

20.12

37.42

42.45

49.54

65.22

10

12

11

14

18

CGBA

5.21

8.87

12.54

17.32

19.15

59.16

91.32

138.74

192.17

215.53

45

95

104

162

165

Ours

29.77

35.64

38.94

47.71

49.82

10.08

24.51

35.06

31.71

40.36

2

3

4

3

3

ShuffleNetv2

Sign-OPT

–

–

7.03

8.17

9.80

–

–

264.16

266.86

313.85

–

–

262

262

273

Bandits

46.08

48.63

53.46

57.74

61.54

25.14

46.79

64.81

80.80

105.21

8

18

26

29

40

Rays

30.61

47.71

58.27

60.98

69.61

64.88

100.25

129.83

152.97

173.68

60

90.5

109

127

141

Tangent

8.01

8.66

8.01

8.33

8.17

12.69

24.27

27.62

28.17

57.64

11

11

11

11

11

TA

32.35

36.11

38.56

40.36

41.99

22.46

31.78

41.78

47.26

56.74

10.05

10

15

19

18

CGBA

7.84

13.56

18.14

23.53

27.94

72.75

117.12

155.18

194.99

241.50

93

106

157

160

228

Ours

50.82

53.76

58.74

61.21

65.88

7.73

12.11

17.44

19.97

31.31

1

2

2

2

2

16

VGG-16

Sign-OPT

–

–

7.43

9.40

10.94

–

–

258.72

274.02

289.83

–

–

257

270

269

Bandits

47.14

63.64

60.94

58.11

76.06

26.36

46.69

66.86

83.26

107.32

14

24

30

32

44

Rays

29.92

45.14

61.34

69.61

74.16

69.80

106.72

144.76

168.45

195.82

72

101

131

148.5

163

Tangent

11.78

11.78

11.64

12.90

13.60

17.76

31.93

36.09

52.86

57.12

11

11

11

11

11

TA

53.72

60.45

61.29

59.19

61.99

15.12

25.61

36.08

36.19

42.51

8

10

13

10

10

CGBA

10.80

16.83

24.26

31.98

36.47

66.95

95.88

141.29

194.05

227.48

54

96

151

163

224

Ours

64.97

67.44

70.79

71.20

78.84

9.05

11.95

18.09

17.83

28.58

1

1

1

1

1

MobileNetv2

Sign-OPT

–

–

10.56

11.13

13.52

–

–

264.23

272.06

294.81

–

–

263

268

269

Bandits

34.85

42.42

52.31

56.84

68.12

23.65

47.20

66.63

87.53

115.71

10

14

20

27

42

Rays

20.14

29.44

43.86

55.15

61.35

65.73

95.56

150.64

194.50

220.72

60

93

134

196

224

Tangent

11.69

12.25

12.25

12.96

14.08

15.97

21.68

39.32

42.07

77.54

11

11

11

11

11

TA

46.48

48.87

50.85

51.13

52.39

20.66

29.80

36.10

40.07

51.54

7

11

11

12

14

CGBA

10.99

15.77

20.85

26.34

31.97

55.63

82.38

113.97

167.17

209.34

45

52.5

95.5

153

161

Ours

54.81

58.02

59.39

60.92

63.74

9.75

15.63

23.40

24.62

26.46

1

1

1

1

1

ShuffleNetv2

Sign-OPT

–

–

15.69

17.49

19.94

–

–

266.94

270.48

306.49

–

–

268

267

277.5

Bandits

43.33

46.65

55.85

64.70

72.83

19.71

33.76

44.29

55.39

64.94

10

12

12

14

16

Rays

30.08

37.69

43.01

48.40

61.50

59.76

89.20

112.59

127.91

139.31

57

75

84

96

102.5

Tangent

23.20

22.39

22.88

23.69

23.37

17.01

33.34

32.24

50.87

52.71

11

11

11

11

11

TA

43.73

46.99

50.59

53.26

64.02

15.23

22.92

31.56

29.37

42.94

5

6

6

6

8

CGBA

14.38

22.39

32.35

37.58

42.81

71.03

94.04

13.76

180.45

214.59

91.5

95

131

157

218

Ours

47.31

54.85

58.21

66.54

71.67

8.18

12.51

22.28

26.80

33.01

1

1

1

1

1

  1. The bold results are the best
  2. We report the attack success rate (ASR (%)), average query number, and median query number under the max query limited in 100, 200, 300, 400 and 500, respectively