Skip to content

Image adversarial attacks

Generate adversarial perturbations that cause vision models to misclassify - SimBA, NES, ZOO, HopSkipJump.

These attacks generate adversarial perturbations to images that cause vision models to misclassify. Import from dreadnode.airt.

Iterative random perturbation. Adds small random changes to image pixels and keeps changes that move the model toward misclassification.

from dreadnode.airt import simba_attack

Black-box gradient estimation using natural evolution strategies. Estimates gradients without access to model internals.

from dreadnode.airt import nes_attack

Coordinate-wise gradient estimation. Approximates gradients one pixel at a time for targeted misclassification.

from dreadnode.airt import zoo_attack

Decision-based attack that only needs the model’s final prediction (not confidence scores). Works with the least model access.

from dreadnode.airt import hopskipjump_attack