{"id":"https://openalex.org/W4293517971","doi":"https://doi.org/10.1109/icme52920.2022.9859856","title":"Towards Black-Box Adversarial Attacks on Interpretable Deep Learning Systems","display_name":"Towards Black-Box Adversarial Attacks on Interpretable Deep Learning Systems","publication_year":2022,"publication_date":"2022-07-18","ids":{"openalex":"https://openalex.org/W4293517971","doi":"https://doi.org/10.1109/icme52920.2022.9859856"},"language":"en","primary_location":{"id":"doi:10.1109/icme52920.2022.9859856","is_oa":false,"landing_page_url":"https://doi.org/10.1109/icme52920.2022.9859856","pdf_url":null,"source":{"id":"https://openalex.org/S4363607799","display_name":"2022 IEEE International Conference on Multimedia and Expo (ICME)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2022 IEEE International Conference on Multimedia and Expo (ICME)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5100560449","display_name":"Yike Zhan","orcid":null},"institutions":[{"id":"https://openalex.org/I37461747","display_name":"Wuhan University","ror":"https://ror.org/033vjfk17","country_code":"CN","type":"education","lineage":["https://openalex.org/I37461747"]},{"id":"https://openalex.org/I4210154851","display_name":"Hubei University of Education","ror":"https://ror.org/04f41cb79","country_code":"CN","type":"education","lineage":["https://openalex.org/I4210154851"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yike Zhan","raw_affiliation_strings":["School of Cyber Science and Engineering, Wuhan University,Key Laboratory of Aerospace Information Security and Trusted Computing, Ministry of Education,Hubei,China","Key Laboratory of Aerospace Information Security and Trusted Computing, Ministry of Education, School of Cyber Science and Engineering, Wuhan University, Hubei, China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"School of Cyber Science and Engineering, Wuhan University,Key Laboratory of Aerospace Information Security and Trusted Computing, Ministry of Education,Hubei,China","institution_ids":["https://openalex.org/I4210154851"]},{"raw_affiliation_string":"Key Laboratory of Aerospace Information Security and Trusted Computing, Ministry of Education, School of Cyber Science and Engineering, Wuhan University, Hubei, China","institution_ids":["https://openalex.org/I37461747"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5065046158","display_name":"Baolin Zheng","orcid":"https://orcid.org/0009-0002-0381-0255"},"institutions":[{"id":"https://openalex.org/I37461747","display_name":"Wuhan University","ror":"https://ror.org/033vjfk17","country_code":"CN","type":"education","lineage":["https://openalex.org/I37461747"]},{"id":"https://openalex.org/I4210154851","display_name":"Hubei University of Education","ror":"https://ror.org/04f41cb79","country_code":"CN","type":"education","lineage":["https://openalex.org/I4210154851"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Baolin Zheng","raw_affiliation_strings":["School of Cyber Science and Engineering, Wuhan University,Key Laboratory of Aerospace Information Security and Trusted Computing, Ministry of Education,Hubei,China","Key Laboratory of Aerospace Information Security and Trusted Computing, Ministry of Education, School of Cyber Science and Engineering, Wuhan University, Hubei, China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"School of Cyber Science and Engineering, Wuhan University,Key Laboratory of Aerospace Information Security and Trusted Computing, Ministry of Education,Hubei,China","institution_ids":["https://openalex.org/I4210154851"]},{"raw_affiliation_string":"Key Laboratory of Aerospace Information Security and Trusted Computing, Ministry of Education, School of Cyber Science and Engineering, Wuhan University, Hubei, China","institution_ids":["https://openalex.org/I37461747"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100391116","display_name":"Qian Wang","orcid":"https://orcid.org/0000-0002-8967-8525"},"institutions":[{"id":"https://openalex.org/I37461747","display_name":"Wuhan University","ror":"https://ror.org/033vjfk17","country_code":"CN","type":"education","lineage":["https://openalex.org/I37461747"]},{"id":"https://openalex.org/I4210154851","display_name":"Hubei University of Education","ror":"https://ror.org/04f41cb79","country_code":"CN","type":"education","lineage":["https://openalex.org/I4210154851"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Qian Wang","raw_affiliation_strings":["School of Cyber Science and Engineering, Wuhan University,Key Laboratory of Aerospace Information Security and Trusted Computing, Ministry of Education,Hubei,China","Key Laboratory of Aerospace Information Security and Trusted Computing, Ministry of Education, School of Cyber Science and Engineering, Wuhan University, Hubei, China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"School of Cyber Science and Engineering, Wuhan University,Key Laboratory of Aerospace Information Security and Trusted Computing, Ministry of Education,Hubei,China","institution_ids":["https://openalex.org/I4210154851"]},{"raw_affiliation_string":"Key Laboratory of Aerospace Information Security and Trusted Computing, Ministry of Education, School of Cyber Science and Engineering, Wuhan University, Hubei, China","institution_ids":["https://openalex.org/I37461747"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5043542221","display_name":"Ningping Mou","orcid":null},"institutions":[{"id":"https://openalex.org/I37461747","display_name":"Wuhan University","ror":"https://ror.org/033vjfk17","country_code":"CN","type":"education","lineage":["https://openalex.org/I37461747"]},{"id":"https://openalex.org/I4210154851","display_name":"Hubei University of Education","ror":"https://ror.org/04f41cb79","country_code":"CN","type":"education","lineage":["https://openalex.org/I4210154851"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Ningping Mou","raw_affiliation_strings":["School of Cyber Science and Engineering, Wuhan University,Key Laboratory of Aerospace Information Security and Trusted Computing, Ministry of Education,Hubei,China","Key Laboratory of Aerospace Information Security and Trusted Computing, Ministry of Education, School of Cyber Science and Engineering, Wuhan University, Hubei, China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"School of Cyber Science and Engineering, Wuhan University,Key Laboratory of Aerospace Information Security and Trusted Computing, Ministry of Education,Hubei,China","institution_ids":["https://openalex.org/I4210154851"]},{"raw_affiliation_string":"Key Laboratory of Aerospace Information Security and Trusted Computing, Ministry of Education, School of Cyber Science and Engineering, Wuhan University, Hubei, China","institution_ids":["https://openalex.org/I37461747"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5032766697","display_name":"Binqing Guo","orcid":null},"institutions":[{"id":"https://openalex.org/I37461747","display_name":"Wuhan University","ror":"https://ror.org/033vjfk17","country_code":"CN","type":"education","lineage":["https://openalex.org/I37461747"]},{"id":"https://openalex.org/I4210154851","display_name":"Hubei University of Education","ror":"https://ror.org/04f41cb79","country_code":"CN","type":"education","lineage":["https://openalex.org/I4210154851"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Binqing Guo","raw_affiliation_strings":["School of Cyber Science and Engineering, Wuhan University,Key Laboratory of Aerospace Information Security and Trusted Computing, Ministry of Education,Hubei,China","Key Laboratory of Aerospace Information Security and Trusted Computing, Ministry of Education, School of Cyber Science and Engineering, Wuhan University, Hubei, China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"School of Cyber Science and Engineering, Wuhan University,Key Laboratory of Aerospace Information Security and Trusted Computing, Ministry of Education,Hubei,China","institution_ids":["https://openalex.org/I4210154851"]},{"raw_affiliation_string":"Key Laboratory of Aerospace Information Security and Trusted Computing, Ministry of Education, School of Cyber Science and Engineering, Wuhan University, Hubei, China","institution_ids":["https://openalex.org/I37461747"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100706785","display_name":"Qi Li","orcid":"https://orcid.org/0000-0003-1896-7044"},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Qi Li","raw_affiliation_strings":["Institute of Network Sciences and Cyberspace &#x0026; BNRist, Tsinghua University,Beijing,China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Institute of Network Sciences and Cyberspace &#x0026; BNRist, Tsinghua University,Beijing,China","institution_ids":["https://openalex.org/I99065089"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101843177","display_name":"Chao Shen","orcid":"https://orcid.org/0000-0002-6959-0569"},"institutions":[{"id":"https://openalex.org/I87445476","display_name":"Xi'an Jiaotong University","ror":"https://ror.org/017zhmm22","country_code":"CN","type":"education","lineage":["https://openalex.org/I87445476"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Chao Shen","raw_affiliation_strings":["School of Cyber Science and Engineering, Xi&#x0027;an Jiaotong University,Shaanxi,China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"School of Cyber Science and Engineering, Xi&#x0027;an Jiaotong University,Shaanxi,China","institution_ids":["https://openalex.org/I87445476"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5100390514","display_name":"Cong Wang","orcid":"https://orcid.org/0000-0003-0547-315X"},"institutions":[{"id":"https://openalex.org/I168719708","display_name":"City University of Hong Kong","ror":"https://ror.org/03q8dnn23","country_code":"HK","type":"education","lineage":["https://openalex.org/I168719708"]}],"countries":["HK"],"is_corresponding":false,"raw_author_name":"Cong Wang","raw_affiliation_strings":["City University of Hong Kong,Departrnent of Computer Science,HK SAR, China","Departrnent of Computer Science, City University of Hong Kong, HK SAR, China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"City University of Hong Kong,Departrnent of Computer Science,HK SAR, China","institution_ids":["https://openalex.org/I168719708"]},{"raw_affiliation_string":"Departrnent of Computer Science, City University of Hong Kong, HK SAR, China","institution_ids":["https://openalex.org/I168719708"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":8,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.6229,"has_fulltext":false,"cited_by_count":7,"citation_normalized_percentile":{"value":0.6754837,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":90,"max":98},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"6"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12026","display_name":"Explainable Artificial Intelligence (XAI)","score":0.9972000122070312,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9652000069618225,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/interpretability","display_name":"Interpretability","score":0.9296207427978516},{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.8759986162185669},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7751001119613647},{"id":"https://openalex.org/keywords/black-box","display_name":"Black box","score":0.7292108535766602},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.6761554479598999},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.6121803522109985},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.6118748784065247},{"id":"https://openalex.org/keywords/intersection","display_name":"Intersection (aeronautics)","score":0.6082146167755127},{"id":"https://openalex.org/keywords/class","display_name":"Class (philosophy)","score":0.5865820646286011},{"id":"https://openalex.org/keywords/focus","display_name":"Focus (optics)","score":0.5013694763183594},{"id":"https://openalex.org/keywords/deep-neural-networks","display_name":"Deep neural networks","score":0.49903178215026855},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.420674204826355},{"id":"https://openalex.org/keywords/engineering","display_name":"Engineering","score":0.07913002371788025}],"concepts":[{"id":"https://openalex.org/C2781067378","wikidata":"https://www.wikidata.org/wiki/Q17027399","display_name":"Interpretability","level":2,"score":0.9296207427978516},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.8759986162185669},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7751001119613647},{"id":"https://openalex.org/C94966114","wikidata":"https://www.wikidata.org/wiki/Q29256","display_name":"Black box","level":2,"score":0.7292108535766602},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.6761554479598999},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.6121803522109985},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.6118748784065247},{"id":"https://openalex.org/C64543145","wikidata":"https://www.wikidata.org/wiki/Q162942","display_name":"Intersection (aeronautics)","level":2,"score":0.6082146167755127},{"id":"https://openalex.org/C2777212361","wikidata":"https://www.wikidata.org/wiki/Q5127848","display_name":"Class (philosophy)","level":2,"score":0.5865820646286011},{"id":"https://openalex.org/C192209626","wikidata":"https://www.wikidata.org/wiki/Q190909","display_name":"Focus (optics)","level":2,"score":0.5013694763183594},{"id":"https://openalex.org/C2984842247","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep neural networks","level":3,"score":0.49903178215026855},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.420674204826355},{"id":"https://openalex.org/C127413603","wikidata":"https://www.wikidata.org/wiki/Q11023","display_name":"Engineering","level":0,"score":0.07913002371788025},{"id":"https://openalex.org/C146978453","wikidata":"https://www.wikidata.org/wiki/Q3798668","display_name":"Aerospace engineering","level":1,"score":0.0},{"id":"https://openalex.org/C120665830","wikidata":"https://www.wikidata.org/wiki/Q14620","display_name":"Optics","level":1,"score":0.0},{"id":"https://openalex.org/C121332964","wikidata":"https://www.wikidata.org/wiki/Q413","display_name":"Physics","level":0,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/icme52920.2022.9859856","is_oa":false,"landing_page_url":"https://doi.org/10.1109/icme52920.2022.9859856","pdf_url":null,"source":{"id":"https://openalex.org/S4363607799","display_name":"2022 IEEE International Conference on Multimedia and Expo (ICME)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2022 IEEE International Conference on Multimedia and Expo (ICME)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"score":0.8299999833106995,"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16"}],"awards":[{"id":"https://openalex.org/G3211872528","display_name":null,"funder_award_id":"U20B2049,U21B2018,62161160337,62132011","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G8075392316","display_name":null,"funder_award_id":"2020AAA0107701","funder_id":"https://openalex.org/F4320335777","funder_display_name":"National Key Research and Development Program of China"}],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"},{"id":"https://openalex.org/F4320335777","display_name":"National Key Research and Development Program of China","ror":null}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":42,"referenced_works":["https://openalex.org/W1673923490","https://openalex.org/W2096733369","https://openalex.org/W2194775991","https://openalex.org/W2295107390","https://openalex.org/W2591927543","https://openalex.org/W2606462007","https://openalex.org/W2809376420","https://openalex.org/W2883285025","https://openalex.org/W2913039310","https://openalex.org/W2915002466","https://openalex.org/W2947657997","https://openalex.org/W2950782995","https://openalex.org/W2962843949","https://openalex.org/W2962858109","https://openalex.org/W2963062382","https://openalex.org/W2963070423","https://openalex.org/W2963150697","https://openalex.org/W2963715038","https://openalex.org/W2963857521","https://openalex.org/W2964346747","https://openalex.org/W2972986629","https://openalex.org/W2976017709","https://openalex.org/W3015625436","https://openalex.org/W3022179901","https://openalex.org/W3035258980","https://openalex.org/W3084937072","https://openalex.org/W3101609372","https://openalex.org/W4288103143","https://openalex.org/W4293846201","https://openalex.org/W4297666078","https://openalex.org/W6635292102","https://openalex.org/W6734815144","https://openalex.org/W6738549535","https://openalex.org/W6739868092","https://openalex.org/W6746608116","https://openalex.org/W6750404860","https://openalex.org/W6752985256","https://openalex.org/W6753044988","https://openalex.org/W6756943956","https://openalex.org/W6758853676","https://openalex.org/W6779361924","https://openalex.org/W6782269215"],"related_works":["https://openalex.org/W2797441709","https://openalex.org/W2346578521","https://openalex.org/W4297660007","https://openalex.org/W4377704659","https://openalex.org/W2886918272","https://openalex.org/W4387589990","https://openalex.org/W2943982549","https://openalex.org/W3101055019","https://openalex.org/W2910028250","https://openalex.org/W4241566321"],"abstract_inverted_index":{"Recent":[0],"works":[1],"have":[2,76],"empirically":[3],"shown":[4],"that":[5,68,104],"neural":[6],"network":[7],"interpretability":[8],"is":[9,30],"susceptible":[10],"to":[11,44,80,95],"malicious":[12],"manipulations.":[13],"However,":[14],"existing":[15],"attacks":[16],"against":[17],"Interpretable":[18],"Deep":[19],"Learning":[20],"Systems":[21],"(IDLSes)":[22],"all":[23,106],"focus":[24],"on":[25,88],"the":[26,41,48,72,97,107],"white-box":[27],"setting,":[28],"which":[29,63],"obviously":[31],"unpractical":[32],"in":[33,47,105],"real-world":[34],"scenarios.":[35],"In":[36],"this":[37],"paper,":[38],"we":[39],"make":[40],"first":[42],"attempt":[43],"attack":[45,112],"IDLSes":[46],"decision-based":[49],"black-box":[50],"setting.":[51],"We":[52,84],"propose":[53],"a":[54],"new":[55],"framework":[56],"called":[57],"Dual":[58],"Black-box":[59],"Adversarial":[60],"Attack":[61],"(DBAA)":[62],"can":[64],"generate":[65],"adversarial":[66],"examples":[67],"are":[69],"misclassified":[70],"as":[71],"target":[73],"class,":[74],"yet":[75],"very":[77],"similar":[78],"interpretations":[79],"their":[81],"benign":[82],"cases.":[83],"conduct":[85],"comprehensive":[86],"experiments":[87],"different":[89],"combinations":[90],"of":[91,99],"classifiers":[92],"and":[93,115],"interpreters":[94],"illustrate":[96],"effectiveness":[98],"DBAA.":[100],"Empirical":[101],"results":[102],"show":[103],"cases,":[108],"DBAA":[109],"achieves":[110],"high":[111],"success":[113],"rates":[114],"Intersection":[116],"over":[117],"Union":[118],"(IoU)":[119],"scores.":[120]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":2},{"year":2024,"cited_by_count":1},{"year":2023,"cited_by_count":3}],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-10T00:00:00"}
