Abstract: Highlights•A reasonable low-query scenario adapted to the query limitation defense.•Gradient preference helps us to design the gradient-aligned CE (GACE) loss to estimate the gradient precisely.•Gradient-aligned attack (GAA) adapts to the low-query scenario using GACE loss with minimal perturbation.•Extended experiments are conducted to evaluate the effectiveness of our methods on ImageNet, CIFAR10 and Imagga API.
External IDs:doi:10.1016/j.ins.2024.121013
Loading