Next Article in Journal
Designing Personalization Cues for Museum Robots: Docent Observation and Controlled Studies
Previous Article in Journal
AI-Driven Resilient Fault Diagnosis of Bearings in Rotating Machinery
Previous Article in Special Issue
An Explainable Hybrid CNN–Transformer Architecture for Visual Malware Classification
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
This is an early access version, the complete PDF, HTML, and XML versions will be available soon.
Article

FP-ZOO: Fast Patch-Based Zeroth Order Optimization for Black-Box Adversarial Attacks on Vision Models

1
Telecommunications Technology Association, Bundang-ro 47, Bundang-gu, Seongnam-si 13591, Gyeonggi-do, Republic of Korea
2
Department of Smart Security, Gachon University, Seongnam-daero, Sujeong-gu, Seongnam-si 1332, Gyeonggi-do, Republic of Korea
*
Author to whom correspondence should be addressed.
Sensors 2025, 25(22), 7093; https://doi.org/10.3390/s25227093
Submission received: 19 October 2025 / Revised: 12 November 2025 / Accepted: 19 November 2025 / Published: 20 November 2025
(This article belongs to the Special Issue Cyber Security and AI—2nd Edition)

Abstract

Deep neural networks have outperformed conventional methods in various fields such as image recognition, natural language processing, and speech recognition. In particular, vision models are widely applied to real-world domains including medical image analysis, autonomous driving, smart factories, and security surveillance. However, these models are vulnerable to adversarial attacks, which pose serious threats to safety and reliability. Among different attack types, this study focuses on evasion attacks that perturb the inputs of deployed models, with an emphasis on black-box settings. The zeroth order optimization (ZOO) attack can approximate gradients and execute attacks without access to internal model information, but it becomes inefficient and exhibits low success rates on high-resolution images due to its dependence on image resizing and its high memory complexity. To address these limitations, this study proposes a patch-based fast zeroth order optimization attack, FP-ZOO. FP-ZOO partitions images into patches and generates perturbations effectively by employing probability-based sampling and an ϵ-greedy scheduling strategy. We conducted a large-scale evaluation of the FP-ZOO attack on the CIFAR-10, CIFAR-100, and ImageNet datasets. In this evaluation, we adopted attack success rate, L2 distance, and adversarial example generation time as performance metrics. The evaluation results showed that the FP-ZOO attack not only achieved an attack success rate of 97–100% against ImageNet in untargeted attacks, but also demonstrated performance up to 10 s faster compared to the ZOO attack. However, in targeted attacks, it showed relatively lower performance compared to baseline attacks, leaving it as a future research topic.
Keywords: adversarial attack; evasion attack; black-box attack; zeroth order optimization; vision model adversarial attack; evasion attack; black-box attack; zeroth order optimization; vision model

Share and Cite

MDPI and ACS Style

Seo, J.; Jeon, S. FP-ZOO: Fast Patch-Based Zeroth Order Optimization for Black-Box Adversarial Attacks on Vision Models. Sensors 2025, 25, 7093. https://doi.org/10.3390/s25227093

AMA Style

Seo J, Jeon S. FP-ZOO: Fast Patch-Based Zeroth Order Optimization for Black-Box Adversarial Attacks on Vision Models. Sensors. 2025; 25(22):7093. https://doi.org/10.3390/s25227093

Chicago/Turabian Style

Seo, Junho, and Seungho Jeon. 2025. "FP-ZOO: Fast Patch-Based Zeroth Order Optimization for Black-Box Adversarial Attacks on Vision Models" Sensors 25, no. 22: 7093. https://doi.org/10.3390/s25227093

APA Style

Seo, J., & Jeon, S. (2025). FP-ZOO: Fast Patch-Based Zeroth Order Optimization for Black-Box Adversarial Attacks on Vision Models. Sensors, 25(22), 7093. https://doi.org/10.3390/s25227093

Note that from the first issue of 2016, this journal uses article numbers instead of page numbers. See further details here.

Article Metrics

Article metric data becomes available approximately 24 hours after publication online.
Back to TopTop