{"id":"https://openalex.org/W2978877183","doi":"https://doi.org/10.1109/ijcnn.2019.8852078","title":"Targeted Black-Box Adversarial Attack Method for Image Classification Models","display_name":"Targeted Black-Box Adversarial Attack Method for Image Classification Models","publication_year":2019,"publication_date":"2019-07-01","ids":{"openalex":"https://openalex.org/W2978877183","doi":"https://doi.org/10.1109/ijcnn.2019.8852078","mag":"2978877183"},"language":"en","primary_location":{"id":"doi:10.1109/ijcnn.2019.8852078","is_oa":false,"landing_page_url":"https://doi.org/10.1109/ijcnn.2019.8852078","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2019 International Joint Conference on Neural Networks (IJCNN)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5089383615","display_name":"Zheng Su","orcid":"https://orcid.org/0000-0002-1414-6970"},"institutions":[{"id":"https://openalex.org/I24943067","display_name":"Fudan University","ror":"https://ror.org/013q1eq08","country_code":"CN","type":"education","lineage":["https://openalex.org/I24943067"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Su Zheng","raw_affiliation_strings":["State Key Laboratory of ASIC & System, Fudan University, Shanghai, China"],"affiliations":[{"raw_affiliation_string":"State Key Laboratory of ASIC & System, Fudan University, Shanghai, China","institution_ids":["https://openalex.org/I24943067"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100339552","display_name":"Jialin Chen","orcid":"https://orcid.org/0009-0007-0909-4620"},"institutions":[{"id":"https://openalex.org/I24943067","display_name":"Fudan University","ror":"https://ror.org/013q1eq08","country_code":"CN","type":"education","lineage":["https://openalex.org/I24943067"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Jialin Chen","raw_affiliation_strings":["State Key Laboratory of ASIC & System, Fudan University, Shanghai, China"],"affiliations":[{"raw_affiliation_string":"State Key Laboratory of ASIC & System, Fudan University, Shanghai, China","institution_ids":["https://openalex.org/I24943067"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5002732486","display_name":"Lingli Wang","orcid":"https://orcid.org/0000-0002-0579-3527"},"institutions":[{"id":"https://openalex.org/I24943067","display_name":"Fudan University","ror":"https://ror.org/013q1eq08","country_code":"CN","type":"education","lineage":["https://openalex.org/I24943067"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Lingli Wang","raw_affiliation_strings":["State Key Laboratory of ASIC & System, Fudan University, Shanghai, China"],"affiliations":[{"raw_affiliation_string":"State Key Laboratory of ASIC & System, Fudan University, Shanghai, China","institution_ids":["https://openalex.org/I24943067"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5089383615"],"corresponding_institution_ids":["https://openalex.org/I24943067"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":1,"citation_normalized_percentile":{"value":0.11829721,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":90,"max":94},"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9470999836921692,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7449820637702942},{"id":"https://openalex.org/keywords/pixel","display_name":"Pixel","score":0.6167579889297485},{"id":"https://openalex.org/keywords/image","display_name":"Image (mathematics)","score":0.5844627022743225},{"id":"https://openalex.org/keywords/reliability","display_name":"Reliability (semiconductor)","score":0.5724496841430664},{"id":"https://openalex.org/keywords/black-box","display_name":"Black box","score":0.56624436378479},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.5536483526229858},{"id":"https://openalex.org/keywords/contextual-image-classification","display_name":"Contextual image classification","score":0.5510497689247131},{"id":"https://openalex.org/keywords/naive-bayes-classifier","display_name":"Naive Bayes classifier","score":0.5473244190216064},{"id":"https://openalex.org/keywords/decision-tree","display_name":"Decision tree","score":0.5399221777915955},{"id":"https://openalex.org/keywords/random-forest","display_name":"Random forest","score":0.5038558840751648},{"id":"https://openalex.org/keywords/set","display_name":"Set (abstract data type)","score":0.4948391318321228},{"id":"https://openalex.org/keywords/pattern-recognition","display_name":"Pattern recognition (psychology)","score":0.48150691390037537},{"id":"https://openalex.org/keywords/deep-neural-networks","display_name":"Deep neural networks","score":0.4694760739803314},{"id":"https://openalex.org/keywords/class","display_name":"Class (philosophy)","score":0.45783355832099915},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.4497806131839752},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.4248260259628296},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.3986464738845825},{"id":"https://openalex.org/keywords/support-vector-machine","display_name":"Support vector machine","score":0.12239101529121399}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7449820637702942},{"id":"https://openalex.org/C160633673","wikidata":"https://www.wikidata.org/wiki/Q355198","display_name":"Pixel","level":2,"score":0.6167579889297485},{"id":"https://openalex.org/C115961682","wikidata":"https://www.wikidata.org/wiki/Q860623","display_name":"Image (mathematics)","level":2,"score":0.5844627022743225},{"id":"https://openalex.org/C43214815","wikidata":"https://www.wikidata.org/wiki/Q7310987","display_name":"Reliability (semiconductor)","level":3,"score":0.5724496841430664},{"id":"https://openalex.org/C94966114","wikidata":"https://www.wikidata.org/wiki/Q29256","display_name":"Black box","level":2,"score":0.56624436378479},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5536483526229858},{"id":"https://openalex.org/C75294576","wikidata":"https://www.wikidata.org/wiki/Q5165192","display_name":"Contextual image classification","level":3,"score":0.5510497689247131},{"id":"https://openalex.org/C52001869","wikidata":"https://www.wikidata.org/wiki/Q812530","display_name":"Naive Bayes classifier","level":3,"score":0.5473244190216064},{"id":"https://openalex.org/C84525736","wikidata":"https://www.wikidata.org/wiki/Q831366","display_name":"Decision tree","level":2,"score":0.5399221777915955},{"id":"https://openalex.org/C169258074","wikidata":"https://www.wikidata.org/wiki/Q245748","display_name":"Random forest","level":2,"score":0.5038558840751648},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.4948391318321228},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.48150691390037537},{"id":"https://openalex.org/C2984842247","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep neural networks","level":3,"score":0.4694760739803314},{"id":"https://openalex.org/C2777212361","wikidata":"https://www.wikidata.org/wiki/Q5127848","display_name":"Class (philosophy)","level":2,"score":0.45783355832099915},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.4497806131839752},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.4248260259628296},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.3986464738845825},{"id":"https://openalex.org/C12267149","wikidata":"https://www.wikidata.org/wiki/Q282453","display_name":"Support vector machine","level":2,"score":0.12239101529121399},{"id":"https://openalex.org/C62520636","wikidata":"https://www.wikidata.org/wiki/Q944","display_name":"Quantum mechanics","level":1,"score":0.0},{"id":"https://openalex.org/C121332964","wikidata":"https://www.wikidata.org/wiki/Q413","display_name":"Physics","level":0,"score":0.0},{"id":"https://openalex.org/C163258240","wikidata":"https://www.wikidata.org/wiki/Q25342","display_name":"Power (physics)","level":2,"score":0.0},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/ijcnn.2019.8852078","is_oa":false,"landing_page_url":"https://doi.org/10.1109/ijcnn.2019.8852078","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2019 International Joint Conference on Neural Networks (IJCNN)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/15","display_name":"Life in Land","score":0.6100000143051147}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":49,"referenced_works":["https://openalex.org/W1673923490","https://openalex.org/W1799366690","https://openalex.org/W1836465849","https://openalex.org/W1945616565","https://openalex.org/W2018061979","https://openalex.org/W2097117768","https://openalex.org/W2099471712","https://openalex.org/W2108598243","https://openalex.org/W2112796928","https://openalex.org/W2163605009","https://openalex.org/W2194775991","https://openalex.org/W2243397390","https://openalex.org/W2274287116","https://openalex.org/W2274565976","https://openalex.org/W2293078015","https://openalex.org/W2460937040","https://openalex.org/W2531409750","https://openalex.org/W2543927648","https://openalex.org/W2561498661","https://openalex.org/W2727966874","https://openalex.org/W2770312844","https://openalex.org/W2949117887","https://openalex.org/W2952339051","https://openalex.org/W2962700793","https://openalex.org/W2963163009","https://openalex.org/W2963207607","https://openalex.org/W2963446712","https://openalex.org/W2963560523","https://openalex.org/W2964153729","https://openalex.org/W2964350391","https://openalex.org/W3103557498","https://openalex.org/W3118608800","https://openalex.org/W4293718192","https://openalex.org/W4300511536","https://openalex.org/W4320013936","https://openalex.org/W6637162671","https://openalex.org/W6638444622","https://openalex.org/W6638667902","https://openalex.org/W6640425456","https://openalex.org/W6684191040","https://openalex.org/W6694260854","https://openalex.org/W6694611762","https://openalex.org/W6719080892","https://openalex.org/W6731039222","https://openalex.org/W6732520560","https://openalex.org/W6740446203","https://openalex.org/W6746295503","https://openalex.org/W6785841629","https://openalex.org/W6787972765"],"related_works":["https://openalex.org/W4389954502","https://openalex.org/W2771255398","https://openalex.org/W2930428186","https://openalex.org/W3200027047","https://openalex.org/W3125536479","https://openalex.org/W4214820172","https://openalex.org/W4386984454","https://openalex.org/W3120363735","https://openalex.org/W2394323384","https://openalex.org/W4312822655"],"abstract_inverted_index":{"Deep":[0],"neural":[1],"networks":[2],"(DNNs)":[3],"are":[4,18],"widely":[5],"applied":[6],"to":[7,12,27,35,72,103,134,139],"image":[8,79],"classification":[9,28,80],"tasks.":[10],"Due":[11],"the":[13,36,101,104,108,115,129,160],"fact":[14],"that":[15],"these":[16],"models":[17,51],"usually":[19],"vulnerable,":[20],"subtle":[21],"perturbations":[22,42],"of":[23,38,43,91,107,123,148],"pixels":[24,44],"may":[25],"lead":[26],"errors,":[29],"which":[30],"poses":[31],"a":[32,67,121,146,196],"serious":[33],"threat":[34],"success":[37],"DNN":[39],"applications.":[40],"Moreover,":[41],"can":[45,85,118],"also":[46],"corrupt":[47],"other":[48,170],"pattern":[49],"recognition":[50],"such":[52],"as":[53],"Naive":[54],"Bayes":[55],"(NB),":[56],"Decision":[57],"Tree":[58],"(DT)":[59],"and":[60,93,99,166,179,188],"Random":[61],"Forest":[62],"(RF).":[63],"In":[64,157],"this":[65],"paper,":[66],"general":[68],"method":[69,84,117,131,162],"is":[70,132],"proposed":[71,83,116,130,161],"carry":[73],"out":[74],"targeted":[75,87],"black-box":[76,171],"attacks":[77,136,193],"for":[78,137,154],"models.":[81],"The":[82],"achieve":[86,120],"fool":[88],"rates":[89],"(TFRs)":[90],"0.873":[92],"0.781":[94],"on":[95,125,142,190,195],"CIFAR-10":[96,191],"dataset":[97,144],"with":[98,145,174],"without":[100],"access":[102],"training":[105],"set":[106],"target":[109],"model":[110],"respectively.":[111],"For":[112],"cross-model":[113],"attacks,":[114],"still":[119],"TFR":[122,147,178,183],"0.630":[124],"CIFAR-":[126],"10.":[127],"Furthermore,":[128],"able":[133],"mount":[135],"up":[138],"100":[140],"classes":[141],"CIFAR-100":[143],"0.721,":[149],"successfully":[150],"handling":[151],"99":[152],"cases":[153],"each":[155],"class.":[156],"our":[158],"experiments,":[159],"shows":[163],"higher":[164,167],"performance":[165],"reliability":[168],"than":[169,184],"attack":[172],"methods,":[173],"0.123":[175],"greater":[176,181],"maximum":[177],"0.602":[180],"minimum":[182],"previous":[185],"methods":[186],"UPSET":[187],"ANGRI":[189],"in":[192],"trained":[194],"single":[197],"model.":[198]},"counts_by_year":[{"year":2024,"cited_by_count":1}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
