Consensus-based optimization for closed-box adversarial attacks and a connection to evolution strategies
math.OC, cs.LG
Submitted: 2025-06-30
Updated: 2026-09-16
Code: https://github.com/TimRoith/AdversarialCBO
License: http://creativecommons.org/licenses/by/4.0/
The gist: Consensus-based optimization (CBO) has established itself as an efficient gradient-free optimization scheme, with attractive mathematical properties, such as mean-field convergence results for
Terminology
Abstract
Consensus-based optimization (CBO) has established itself as an efficient gradient-free optimization scheme, with attractive mathematical properties, such as mean-field convergence results for non-convex loss functions. In this work, we study CBO in the context of closed-box adversarial attacks, which are imperceptible input perturbations that aim to fool a classifier, without accessing its gradient. Our contribution is to establish a connection between the so-called consensus hopping as introduced by Riedl et al. and natural evolution strategies (NES) commonly applied in the context of adversarial attacks and to rigorously relate both methods to gradient-based optimization schemes. Beyond that, we provide a comprehensive experimental study that shows that despite the conceptual similarities, CBO can outperform NES and other evolutionary strategies in certain scenarios.
Sources
- On the Existence of the Adversarial Bayes Classifier (Extended Version)
- Constrained Consensus-Based Optimization and Numerical Heuristics for the Few Particle Regime
- Exploring the Space of Black-box Attacks on Deep Neural Networks
- A Survey of Black-Box Adversarial Attacks on Computer Vision Models
- Consensus-based algorithms for stochastic optimization problems
- A particle consensus approach to solving nonconvex-nonconcave min-max problems
- MirrorCBO: A consensus-based optimization method in the spirit of mirror descent
- Discrete Consensus-Based Optimization
- An interacting particle consensus method for constrained global optimization
- There are No Bit Parts for Sign Bits in Black-Box Attacks
- Lipschitz regularized Deep Neural Networks generalize and are adversarially robust
- Regularity and positivity of solutions of the Consensus-Based Optimization equation: unconditional global convergence
- CB$^2$O: Consensus-Based Bi-Level Optimization
- Explaining and Harnessing Adversarial Examples
- Micro-Macro Decomposition of Particle Swarm Optimization Methods
- One weird trick for parallelizing convolutional neural networks
- Towards Deep Learning Models Resistant to Adversarial Attacks
- Yet another but more efficient black-box adversarial attack: tiling and evolution strategies
- PyTorch: An Imperative Style, High-Performance Deep Learning Library
- Gradient is All You Need? How Consensus-Based Optimization can be Interpreted as a Stochastic Relaxation of Gradient Descent
Related papers
- Lions and Muons: Optimization via Stochastic Frank-Wolfe under Heavy-Tailed Noise
- Adam-HNAG: A Convergent Reformulation of Adam with Accelerated Rate
- Incremental Learning in Mirror Flows
- Online Control via Counterfactual Tracking
- Asynchronous Replanning in Two Population Linear Quadratic Mean Field Games: Information Requirements and Stability
- Petrov-Galerkin operator inference with application to stability-encouraging identification