The invention belongs to the technical field of black-box confrontation attacks, discloses a black-box confrontation
attack method based on proxy
function optimization and feature probability
diffusion, and aims to solve the problems that traditional evading attacks cannot disturb a
network intrusion detection system based on
machine learning and the number of black-box confrontation sample
attack query times is large. In order to solve the problems of large calculation overhead, universality of adversarial samples and the like, a method for generating the adversarial samples by combining the adversarial samples,
reinforcement learning and a
diffusion model is designed, an indirect optimization framework is realized, and a trainable neural network is introduced for generating adversarial disturbance. Through back propagation of the proxy
loss function J, parameters of the neural network can be indirectly updated. According to the mechanism, an unguidable
black box optimization problem is ingeniously converted into a trainable and end-to-end neural network
optimization problem, so that indirect optimization against disturbance is realized.