{"id":"https://openalex.org/W3167676691","doi":"https://doi.org/10.1109/cvpr46437.2021.01166","title":"Simulating Unknown Target Models for Query-Efficient Black-box Attacks","display_name":"Simulating Unknown Target Models for Query-Efficient Black-box Attacks","publication_year":2021,"publication_date":"2021-06-01","ids":{"openalex":"https://openalex.org/W3167676691","doi":"https://doi.org/10.1109/cvpr46437.2021.01166","mag":"3167676691"},"language":"en","primary_location":{"id":"doi:10.1109/cvpr46437.2021.01166","is_oa":false,"landing_page_url":"https://doi.org/10.1109/cvpr46437.2021.01166","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2021 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5100410905","display_name":"Chen Ma","orcid":"https://orcid.org/0000-0001-6876-3117"},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Chen Ma","raw_affiliation_strings":["School of Software, BNRist, Tsinghua University, Beijing, China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"School of Software, BNRist, Tsinghua University, Beijing, China","institution_ids":["https://openalex.org/I99065089"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100379250","display_name":"Li Chen","orcid":"https://orcid.org/0000-0002-4761-5913"},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Li Chen","raw_affiliation_strings":["School of Software, BNRist, Tsinghua University, Beijing, China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"School of Software, BNRist, Tsinghua University, Beijing, China","institution_ids":["https://openalex.org/I99065089"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5080894318","display_name":"Jun\u2010Hai Yong","orcid":"https://orcid.org/0000-0002-4326-4167"},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Jun-Hai Yong","raw_affiliation_strings":["School of Software, BNRist, Tsinghua University, Beijing, China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"School of Software, BNRist, Tsinghua University, Beijing, China","institution_ids":["https://openalex.org/I99065089"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":7.2765,"has_fulltext":false,"cited_by_count":65,"citation_normalized_percentile":{"value":0.97572578,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":94,"max":100},"biblio":{"volume":null,"issue":null,"first_page":"11830","last_page":"11839"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11307","display_name":"Domain Adaptation and Few-Shot Learning","score":0.9918000102043152,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10036","display_name":"Advanced Neural Network Applications","score":0.9848999977111816,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8474270105361938},{"id":"https://openalex.org/keywords/generalization","display_name":"Generalization","score":0.5780271887779236},{"id":"https://openalex.org/keywords/black-box","display_name":"Black box","score":0.558425784111023},{"id":"https://openalex.org/keywords/code","display_name":"Code (set theory)","score":0.5195744037628174},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.45034804940223694},{"id":"https://openalex.org/keywords/process","display_name":"Process (computing)","score":0.44166502356529236},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.4251541793346405},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.4208940863609314},{"id":"https://openalex.org/keywords/source-code","display_name":"Source code","score":0.4170178174972534},{"id":"https://openalex.org/keywords/mean-squared-error","display_name":"Mean squared error","score":0.4109414219856262},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.38361334800720215}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8474270105361938},{"id":"https://openalex.org/C177148314","wikidata":"https://www.wikidata.org/wiki/Q170084","display_name":"Generalization","level":2,"score":0.5780271887779236},{"id":"https://openalex.org/C94966114","wikidata":"https://www.wikidata.org/wiki/Q29256","display_name":"Black box","level":2,"score":0.558425784111023},{"id":"https://openalex.org/C2776760102","wikidata":"https://www.wikidata.org/wiki/Q5139990","display_name":"Code (set theory)","level":3,"score":0.5195744037628174},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.45034804940223694},{"id":"https://openalex.org/C98045186","wikidata":"https://www.wikidata.org/wiki/Q205663","display_name":"Process (computing)","level":2,"score":0.44166502356529236},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.4251541793346405},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.4208940863609314},{"id":"https://openalex.org/C43126263","wikidata":"https://www.wikidata.org/wiki/Q128751","display_name":"Source code","level":2,"score":0.4170178174972534},{"id":"https://openalex.org/C139945424","wikidata":"https://www.wikidata.org/wiki/Q1940696","display_name":"Mean squared error","level":2,"score":0.4109414219856262},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.38361334800720215},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.0},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.0},{"id":"https://openalex.org/C134306372","wikidata":"https://www.wikidata.org/wiki/Q7754","display_name":"Mathematical analysis","level":1,"score":0.0},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.0},{"id":"https://openalex.org/C105795698","wikidata":"https://www.wikidata.org/wiki/Q12483","display_name":"Statistics","level":1,"score":0.0},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/cvpr46437.2021.01166","is_oa":false,"landing_page_url":"https://doi.org/10.1109/cvpr46437.2021.01166","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2021 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","score":0.5099999904632568,"id":"https://metadata.un.org/sdg/16"}],"awards":[],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":74,"referenced_works":["https://openalex.org/W9657784","https://openalex.org/W1673923490","https://openalex.org/W1945616565","https://openalex.org/W2117539524","https://openalex.org/W2149479912","https://openalex.org/W2194775991","https://openalex.org/W2461943168","https://openalex.org/W2549139847","https://openalex.org/W2570685808","https://openalex.org/W2603766943","https://openalex.org/W2746600820","https://openalex.org/W2789304371","https://openalex.org/W2883285025","https://openalex.org/W2895097814","https://openalex.org/W2903105043","https://openalex.org/W2915002466","https://openalex.org/W2948963698","https://openalex.org/W2949736877","https://openalex.org/W2950782995","https://openalex.org/W2952104986","https://openalex.org/W2960010704","https://openalex.org/W2962971773","https://openalex.org/W2963062382","https://openalex.org/W2963207607","https://openalex.org/W2963303354","https://openalex.org/W2963384482","https://openalex.org/W2963446712","https://openalex.org/W2963560987","https://openalex.org/W2963595196","https://openalex.org/W2963771536","https://openalex.org/W2963844355","https://openalex.org/W2963857521","https://openalex.org/W2963882994","https://openalex.org/W2964137095","https://openalex.org/W2964153729","https://openalex.org/W2964205597","https://openalex.org/W2964253222","https://openalex.org/W2964318098","https://openalex.org/W2964346747","https://openalex.org/W2966391112","https://openalex.org/W2967540978","https://openalex.org/W2970257215","https://openalex.org/W2971126145","https://openalex.org/W2973414778","https://openalex.org/W2983219069","https://openalex.org/W2984699060","https://openalex.org/W2996649838","https://openalex.org/W2996694668","https://openalex.org/W3015625436","https://openalex.org/W3102964708","https://openalex.org/W3103836116","https://openalex.org/W3106412272","https://openalex.org/W3107235539","https://openalex.org/W3118608800","https://openalex.org/W3163776795","https://openalex.org/W4289549047","https://openalex.org/W4293846201","https://openalex.org/W6637162671","https://openalex.org/W6640425456","https://openalex.org/W6713132643","https://openalex.org/W6731927902","https://openalex.org/W6739868092","https://openalex.org/W6750404860","https://openalex.org/W6752985256","https://openalex.org/W6753044988","https://openalex.org/W6755358392","https://openalex.org/W6759424558","https://openalex.org/W6759580348","https://openalex.org/W6763511984","https://openalex.org/W6763636181","https://openalex.org/W6764550947","https://openalex.org/W6772101090","https://openalex.org/W6787972765","https://openalex.org/W6796082197"],"related_works":["https://openalex.org/W3162204513","https://openalex.org/W2371138613","https://openalex.org/W2048963458","https://openalex.org/W43109613","https://openalex.org/W2359952343","https://openalex.org/W2047881532","https://openalex.org/W2285795935","https://openalex.org/W2080152487","https://openalex.org/W2102148524","https://openalex.org/W3081644756"],"abstract_inverted_index":{"Many":[0],"adversarial":[1],"attacks":[2,22,51,98],"have":[3],"been":[4],"proposed":[5,204],"to":[6,27,59,116,140,181,215],"investigate":[7],"the":[8,16,29,32,36,40,44,70,82,86,97,114,118,121,124,142,158,182,190,195,203,216],"security":[9],"issues":[10],"of":[11,31,72,88,99,129,176,189,212],"deep":[12],"neural":[13],"networks.":[14,102,126],"In":[15],"black-box":[17],"setting,":[18],"current":[19],"model":[20,26,64,152],"stealing":[21],"train":[23,60],"a":[24,61,107,150,171,173],"substitute":[25,63],"counterfeit":[28],"functionality":[30,71,165],"target":[33,41,75,151],"model.":[34,42,76],"However,":[35],"training":[37,83],"requires":[38],"querying":[39],"Consequently,":[43],"query":[45,93,186,207],"complexity":[46,208],"remains":[47],"high,":[48],"and":[49,123,135,144,198],"such":[50],"can":[52,68,161,178],"be":[53,179],"defended":[54],"easily.":[55],"This":[56],"study":[57],"aims":[58],"generalized":[62],"called":[65],"\"Simulator\",":[66],"which":[67],"mimic":[69],"any":[73],"unknown":[74],"To":[77],"this":[78,130],"end,":[79],"we":[80],"build":[81],"data":[84],"with":[85],"form":[87],"multiple":[89,138],"tasks":[90,139],"by":[91,209],"collecting":[92],"sequences":[94],"generated":[95],"during":[96],"various":[100],"existing":[101],"The":[103,127,219],"learning":[104],"process":[105],"uses":[106],"mean":[108],"square":[109],"error-based":[110],"knowledge-distillation":[111],"loss":[112,131],"in":[113,156],"meta-learning":[115],"minimize":[117],"difference":[119],"between":[120],"Simulator":[122,143,160],"sampled":[125],"meta-gradients":[128],"are":[132],"then":[133],"computed":[134],"accumulated":[136],"from":[137],"update":[141],"subsequently":[145],"improve":[146],"generalization.":[147],"When":[148],"attacking":[149],"that":[153,202],"is":[154,223],"unseen":[155],"training,":[157],"trained":[159],"accurately":[162],"simulate":[163],"its":[164,167],"using":[166,194],"limited":[168],"feedback.":[169],"As":[170],"result,":[172],"large":[174],"fraction":[175],"queries":[177],"transferred":[180],"Simulator,":[183],"thereby":[184],"reducing":[185],"complexity.":[187],"Results":[188],"comprehensive":[191],"experiments":[192],"conducted":[193],"CIFAR-10,":[196],"CIFAR-100,":[197],"TinyImageNet":[199],"datasets":[200],"demonstrate":[201],"approach":[205],"reduces":[206],"several":[210],"orders":[211],"magnitude":[213],"compared":[214],"baseline":[217],"method.":[218],"implementation":[220],"source":[221],"code":[222],"released":[224],"online":[225],"<sup":[226],"xmlns:mml=\"http://www.w3.org/1998/Math/MathML\"":[227],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">1</sup>":[228],".":[229]},"counts_by_year":[{"year":2025,"cited_by_count":11},{"year":2024,"cited_by_count":15},{"year":2023,"cited_by_count":15},{"year":2022,"cited_by_count":16},{"year":2021,"cited_by_count":6},{"year":2020,"cited_by_count":2}],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-10T00:00:00"}
