Subspace Attack: Exploiting Promising Subspaces for Query-Efficient Black-box Attacks

Published in Dec, 2019

Yan, Ziang*, Yiwen Guo*, and Changshui Zhang. "Subspace Attack: Exploiting Promising Subspaces for Query-Efficient Black-box Attacks." NeurIPS 2019.

We demonstrate one can mount black-box adversarial attacks in subspaces with much lower dimensionalities than that of original image space. Then, we propose to exploit gradients of a few reference models which arguably span some promising search subspaces.

paper (arxiv version) code