Since the training data for the target model in a data-free black-box attack is not available, most recent schemes utilize GANs to generate data for training substitute model. However, these GANs-based schemes suffer from low training efficiency as the generator needs to be retrained for each target model during the substitute training process, as well as low generation quality. To overcome these limitations, we consider utilizing the diffusion model to generate data, and propose a data-free black-box attack scheme based on diffusion model to improve the efficiency and accuracy of substitute training. Despite the data generated by the diffusion model exhibits high quality, it presents diverse domain distributions and contains many samples that do not meet the discriminative criteria of the target model. To further facilitate the diffusion model to generate data suitable for the target model, we propose a Latent Code Augmentation (LCA) method to guide the diffusion model in generating data. With the guidance of LCA, the data generated by the diffusion model not only meets the discriminative criteria of the target model but also exhibits high diversity. By utilizing this data, it is possible to train substitute model that closely resemble the target model more efficiently. Extensive experiments demonstrate that our LCA achieves higher attack success rates and requires fewer query budgets compared to GANs-based schemes for different target models.
翻译:由于无数据黑盒攻击中目标模型的训练数据不可获取,近期方案多利用生成对抗网络(GANs)生成数据以训练替代模型。然而,此类基于GANs的方案在替代训练过程中需为每个目标模型重新训练生成器,导致训练效率低下,且生成质量欠佳。为突破这些局限,本文考虑利用扩散模型生成数据,并提出一种基于扩散模型的无数据黑盒攻击方案,以提升替代训练的效率与精度。尽管扩散模型生成的数据具有高质量,但其呈现多样的领域分布,且包含大量不满足目标模型判别准则的样本。为促使扩散模型生成更适配目标模型的数据,我们提出潜在码增强(LCA)方法以引导扩散模型进行数据生成。在LCA引导下,扩散模型生成的数据不仅满足目标模型的判别准则,且具有高多样性。利用此类数据可更高效地训练与目标模型高度相似的替代模型。大量实验证明,针对不同目标模型,与基于GANs的方案相比,我们的LCA实现了更高的攻击成功率并消耗更少的查询预算。