Latent Geometric Chords for Query-Efficient Decision-Based Adversarial Attacks

📅 2026-05-29
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
This work addresses the reconstruction distortions commonly observed in existing decision-based black-box adversarial attacks, which often arise from high-frequency artifacts or constraints imposed by low-dimensional manifolds. To overcome these limitations, the authors propose Latent Geometric Chords (LGC), a method that introduces curvature-aware geometric search within a compressed semantic manifold and integrates a Residual Adversarial Generation (RAG) mechanism. This approach directly superimposes semantic perturbations as geometric chords onto the original image, thereby circumventing low-dimensional constraints and substantially expanding the effective search space while preserving visual fidelity. Within only 5,000 queries, LGC achieves high attack success rates with SSIM exceeding 0.99 and LPIPS below 0.01, demonstrates strong cross-dataset transferability, and effectively compromises adversarially trained robust models.
📝 Abstract
While decision-based black-box adversarial attacks present a severe security threat, current methodologies suffer from fundamental limitations. Pixel-wise attacks frequently introduce unnatural, high-frequency visual artifacts, while latent-space frameworks are confined by the limited search space of low-dimensional manifolds and inherent reconstruction flaws. To resolve these limitations, we propose Latent Geometric Chords (LGC) for Query-Efficient Decision-Based Adversarial Attacks alongside a variant, LGC-H. At its core, LGC navigates decision boundaries by executing a curvature-aware geometric search within a compressed semantic manifold. To guarantee high visual fidelity and circumvent dimensionality bottlenecks, we introduce a Residual-based Adversarial Generation (RAG) mechanism. RAG isolates semantic perturbations as geometric chords and superimposes them directly onto the original source image. RAG substantially resolves baseline reconstruction flaws and effectively doubles the permissible search space dimensions. Experimental results demonstrate that LGC achieves robust cross-dataset transferability and substantially outperforms state-of-the-art baselines. Notably, our method, LGC, minimizes perturbation magnitudes while achieving state-of-the-art visual fidelity--with a Structural Similarity Index Measure (SSIM) exceeding 0.99 and a Learned Perceptual Image Patch Similarity (LPIPS) below 0.01 at 5000 queries--and sustaining high attack success rates under stringent perceptual constraints, successfully compromising adversarially trained robust models. The source code is available at: https://github.com/eihmuekhine/Latent-Geometric-Chords.
Problem

Research questions and friction points this paper is trying to address.

decision-based adversarial attacks
visual artifacts
latent space
reconstruction flaws
search space limitations
Innovation

Methods, ideas, or system contributions that make the work stand out.

Latent Geometric Chords
Decision-Based Adversarial Attack
Residual-based Adversarial Generation
Semantic Manifold
Query Efficiency
🔎 Similar Papers
No similar papers found.
E
Ei Hmue Khine
School of Mathematics, Harbin Institute of Technology, Harbin 150001, China
Yao Li
Yao Li
Assistant Professor, Harbin Institute of Technology
Adversarial attackdeep learningbrain computer interface
J
Jiebao Sun
School of Mathematics, Harbin Institute of Technology, Harbin 150001, China
Shengzhu Shi
Shengzhu Shi
Lecturer, Harbin Institute of Technology
uncertainty quantificationdeep learningimage processingoptimal controlpreconditioning
Z
Zhichang Guo
School of Mathematics, Harbin Institute of Technology, Harbin 150001, China
B
Boying Wu
School of Mathematics, Harbin Institute of Technology, Harbin 150001, China