Blacklight: Scalable Defense for Neural Networks against Query-Based Black-Box Attacks

No ratings

Presented at USENIX Security 2022 by

Deep learning systems are known to be vulnerable to adversarial examples. In particular, query-based black-box attacks do not require knowledge of the deep learning model, but can compute adversarial examples over the network by submitting queries and inspecting returns. Recent work largely improves the efficiency of those attacks, demonstrating their practicality on today's ML-as-a-service platforms.