{"id":"https://openalex.org/W4416250044","doi":"https://doi.org/10.1109/ijcnn64981.2025.11228898","title":"ODE: Decision-based Black-box Adversarial Attack through Orthogonal Distribution Evolution","display_name":"ODE: Decision-based Black-box Adversarial Attack through Orthogonal Distribution Evolution","publication_year":2025,"publication_date":"2025-06-30","ids":{"openalex":"https://openalex.org/W4416250044","doi":"https://doi.org/10.1109/ijcnn64981.2025.11228898"},"language":null,"primary_location":{"id":"doi:10.1109/ijcnn64981.2025.11228898","is_oa":false,"landing_page_url":"https://doi.org/10.1109/ijcnn64981.2025.11228898","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 International Joint Conference on Neural Networks (IJCNN)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5101641723","display_name":"Hongyi Liu","orcid":"https://orcid.org/0000-0002-3651-6960"},"institutions":[{"id":"https://openalex.org/I20231570","display_name":"Peking University","ror":"https://ror.org/02v51f717","country_code":"CN","type":"education","lineage":["https://openalex.org/I20231570"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Hongyi Liu","raw_affiliation_strings":["Peking University,School of Software and Microelectronics,Beijing,China"],"affiliations":[{"raw_affiliation_string":"Peking University,School of Software and Microelectronics,Beijing,China","institution_ids":["https://openalex.org/I20231570"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5061731036","display_name":"Yutong Fang","orcid":null},"institutions":[{"id":"https://openalex.org/I20231570","display_name":"Peking University","ror":"https://ror.org/02v51f717","country_code":"CN","type":"education","lineage":["https://openalex.org/I20231570"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yutong Fang","raw_affiliation_strings":["Peking University,School of Software and Microelectronics,Beijing,China"],"affiliations":[{"raw_affiliation_string":"Peking University,School of Software and Microelectronics,Beijing,China","institution_ids":["https://openalex.org/I20231570"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5069358025","display_name":"Tong Jia","orcid":"https://orcid.org/0000-0002-5946-9829"},"institutions":[{"id":"https://openalex.org/I4210100255","display_name":"Beijing Academy of Artificial Intelligence","ror":"https://ror.org/016a74861","country_code":"CN","type":"other","lineage":["https://openalex.org/I4210100255"]},{"id":"https://openalex.org/I20231570","display_name":"Peking University","ror":"https://ror.org/02v51f717","country_code":"CN","type":"education","lineage":["https://openalex.org/I20231570"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Tong Jia","raw_affiliation_strings":["Peking University,Institute for Artificial Intelligence,Beijing,China"],"affiliations":[{"raw_affiliation_string":"Peking University,Institute for Artificial Intelligence,Beijing,China","institution_ids":["https://openalex.org/I4210100255","https://openalex.org/I20231570"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5100414277","display_name":"Ying Li","orcid":"https://orcid.org/0000-0002-6278-2357"},"institutions":[{"id":"https://openalex.org/I20231570","display_name":"Peking University","ror":"https://ror.org/02v51f717","country_code":"CN","type":"education","lineage":["https://openalex.org/I20231570"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Ying Li","raw_affiliation_strings":["Peking University,School of Software and Microelectronics,Beijing,China"],"affiliations":[{"raw_affiliation_string":"Peking University,School of Software and Microelectronics,Beijing,China","institution_ids":["https://openalex.org/I20231570"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5101641723"],"corresponding_institution_ids":["https://openalex.org/I20231570"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.19403784,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"9"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9937000274658203,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9937000274658203,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10036","display_name":"Advanced Neural Network Applications","score":0.0010999999940395355,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11273","display_name":"Advanced Graph Neural Networks","score":0.000699999975040555,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.9343000054359436},{"id":"https://openalex.org/keywords/sample","display_name":"Sample (material)","score":0.4372999966144562},{"id":"https://openalex.org/keywords/vulnerability","display_name":"Vulnerability (computing)","score":0.43320000171661377},{"id":"https://openalex.org/keywords/face","display_name":"Face (sociological concept)","score":0.40459999442100525},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.367000013589859},{"id":"https://openalex.org/keywords/class","display_name":"Class (philosophy)","score":0.3303000032901764},{"id":"https://openalex.org/keywords/distribution","display_name":"Distribution (mathematics)","score":0.32829999923706055},{"id":"https://openalex.org/keywords/deep-neural-networks","display_name":"Deep neural networks","score":0.3118000030517578}],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.9343000054359436},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.5519999861717224},{"id":"https://openalex.org/C198531522","wikidata":"https://www.wikidata.org/wiki/Q485146","display_name":"Sample (material)","level":2,"score":0.4372999966144562},{"id":"https://openalex.org/C95713431","wikidata":"https://www.wikidata.org/wiki/Q631425","display_name":"Vulnerability (computing)","level":2,"score":0.43320000171661377},{"id":"https://openalex.org/C2779304628","wikidata":"https://www.wikidata.org/wiki/Q3503480","display_name":"Face (sociological concept)","level":2,"score":0.40459999442100525},{"id":"https://openalex.org/C126255220","wikidata":"https://www.wikidata.org/wiki/Q141495","display_name":"Mathematical optimization","level":1,"score":0.39739999175071716},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.39739999175071716},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.367000013589859},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.33820000290870667},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.3375000059604645},{"id":"https://openalex.org/C2777212361","wikidata":"https://www.wikidata.org/wiki/Q5127848","display_name":"Class (philosophy)","level":2,"score":0.3303000032901764},{"id":"https://openalex.org/C110121322","wikidata":"https://www.wikidata.org/wiki/Q865811","display_name":"Distribution (mathematics)","level":2,"score":0.32829999923706055},{"id":"https://openalex.org/C2984842247","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep neural networks","level":3,"score":0.3118000030517578},{"id":"https://openalex.org/C774472","wikidata":"https://www.wikidata.org/wiki/Q6760393","display_name":"Margin (machine learning)","level":2,"score":0.30889999866485596},{"id":"https://openalex.org/C12725497","wikidata":"https://www.wikidata.org/wiki/Q810247","display_name":"Baseline (sea)","level":2,"score":0.29660001397132874},{"id":"https://openalex.org/C44292817","wikidata":"https://www.wikidata.org/wiki/Q333871","display_name":"Orthogonal matrix","level":3,"score":0.29269999265670776},{"id":"https://openalex.org/C2779079576","wikidata":"https://www.wikidata.org/wiki/Q17092823","display_name":"Jamming","level":2,"score":0.27880001068115234},{"id":"https://openalex.org/C149441793","wikidata":"https://www.wikidata.org/wiki/Q200726","display_name":"Probability distribution","level":2,"score":0.2705000042915344},{"id":"https://openalex.org/C141934464","wikidata":"https://www.wikidata.org/wiki/Q3305386","display_name":"Local optimum","level":2,"score":0.26660001277923584},{"id":"https://openalex.org/C178650346","wikidata":"https://www.wikidata.org/wiki/Q201984","display_name":"Covariance","level":2,"score":0.2653000056743622},{"id":"https://openalex.org/C185142706","wikidata":"https://www.wikidata.org/wiki/Q1134404","display_name":"Covariance matrix","level":2,"score":0.26019999384880066},{"id":"https://openalex.org/C140779682","wikidata":"https://www.wikidata.org/wiki/Q210868","display_name":"Sampling (signal processing)","level":3,"score":0.25130000710487366}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/ijcnn64981.2025.11228898","is_oa":false,"landing_page_url":"https://doi.org/10.1109/ijcnn64981.2025.11228898","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 International Joint Conference on Neural Networks (IJCNN)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":18,"referenced_works":["https://openalex.org/W2108598243","https://openalex.org/W2119112357","https://openalex.org/W2180612164","https://openalex.org/W2302255633","https://openalex.org/W2746600820","https://openalex.org/W2774644650","https://openalex.org/W2913468054","https://openalex.org/W2963542245","https://openalex.org/W2963857521","https://openalex.org/W2964082701","https://openalex.org/W2969542116","https://openalex.org/W2972986629","https://openalex.org/W2993234371","https://openalex.org/W3015625436","https://openalex.org/W3173859330","https://openalex.org/W4225859735","https://openalex.org/W4256333068","https://openalex.org/W4293846201"],"related_works":[],"abstract_inverted_index":{"Despite":[0],"the":[1,33,37,44,72,79,97,134,137,143,147,151,154,171,175],"remarkable":[2],"performance":[3],"of":[4,46,139],"Deep":[5],"Neural":[6],"Networks":[7],"(DNNs)":[8],"in":[9,20,142,174,209],"many":[10],"domains,":[11],"their":[12,18,104],"vulnerability":[13],"to":[14,32,39,89,146,184,188,205],"adversarial":[15,26,47,51,67,80,120,140,180],"attacks":[16],"limits":[17,103],"application":[19],"real-world":[21],"scenarios.":[22],"Attackers":[23],"can":[24],"craft":[25],"examples":[27],"by":[28],"adding":[29],"imperceptible":[30],"perturbations":[31],"original":[34,73],"samples,":[35],"causing":[36],"DNN":[38],"misclassify.":[40],"To":[41,112],"better":[42,179],"understand":[43],"characteristics":[45],"attacks,":[48],"numerous":[49],"black-box":[50,119],"attack":[52,100,108,121,148,157],"methods":[53,61,87],"have":[54],"been":[55],"proposed,":[56],"particularly":[57],"decision-based":[58],"methods.":[59],"These":[60],"typically":[62],"start":[63],"with":[64],"an":[65,162],"initial":[66],"sample,":[68],"pulling":[69],"it":[70],"toward":[71],"sample":[74],"(attack":[75],"direction),":[76],"while":[77],"preserving":[78],"sample\u2019s":[81],"class":[82],"(fitting":[83],"direction).":[84],"However,":[85],"existing":[86,200],"struggle":[88],"escape":[90,189],"local":[91,190],"optima":[92],"and":[93,99,107,156],"face":[94],"conflicts":[95],"between":[96,153],"fitting":[98,155],"directions,":[101],"which":[102],"query":[105],"efficiency":[106],"success":[109],"rate":[110],"(ASR).":[111],"address":[113],"these":[114],"issues,":[115],"we":[116,160],"propose":[117],"a":[118,129,206],"method":[122,135,197],"based":[123],"on":[124],"orthogonal":[125,144,176],"distribution":[126,138],"evolution.":[127],"Using":[128],"covariance":[130],"matrix":[131],"evolution":[132],"strategy,":[133],"fits":[136],"samples":[141,181],"direction":[145,177],"direction,":[149],"mitigating":[150],"conflict":[152],"directions.":[158],"Additionally,":[159],"design":[161],"adaptive":[163],"search":[164],"step":[165,172],"adjustment":[166],"strategy":[167],"that":[168,195],"probabilistically":[169],"increases":[170],"size":[173],"when":[178],"are":[182],"hard":[183],"find,":[185],"thus":[186],"helping":[187],"optima.":[191],"Experimental":[192],"results":[193],"show":[194],"our":[196],"significantly":[198],"outperforms":[199],"baseline":[201],"methods,":[202],"achieving":[203],"up":[204],"13%":[207],"improvement":[208],"average":[210],"ASR.":[211]},"counts_by_year":[],"updated_date":"2026-03-07T16:01:11.037858","created_date":"2025-11-14T00:00:00"}
