{"id":"https://openalex.org/W4200376481","doi":"https://doi.org/10.1109/pst52912.2021.9647846","title":"Towards Query-efficient Black-box Adversarial Attack on Text Classification Models","display_name":"Towards Query-efficient Black-box Adversarial Attack on Text Classification Models","publication_year":2021,"publication_date":"2021-12-13","ids":{"openalex":"https://openalex.org/W4200376481","doi":"https://doi.org/10.1109/pst52912.2021.9647846"},"language":"en","primary_location":{"id":"doi:10.1109/pst52912.2021.9647846","is_oa":false,"landing_page_url":"https://doi.org/10.1109/pst52912.2021.9647846","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2021 18th International Conference on Privacy, Security and Trust (PST)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5039792020","display_name":"Mohammad Mehdi Yadollahi","orcid":null},"institutions":[],"countries":[],"is_corresponding":true,"raw_author_name":"Mohammad Mehdi Yadollahi","raw_affiliation_strings":["Faculty of Computer Science, UNB Fredericton, Canadian Institute for Cybersecurity (CIC), Canada"],"affiliations":[{"raw_affiliation_string":"Faculty of Computer Science, UNB Fredericton, Canadian Institute for Cybersecurity (CIC), Canada","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5082926585","display_name":"Arash Habibi Lashkari","orcid":"https://orcid.org/0000-0002-1240-6433"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Arash Habibi Lashkari","raw_affiliation_strings":["Faculty of Computer Science, UNB Fredericton, Canadian Institute for Cybersecurity (CIC), Canada"],"affiliations":[{"raw_affiliation_string":"Faculty of Computer Science, UNB Fredericton, Canadian Institute for Cybersecurity (CIC), Canada","institution_ids":[]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5034685391","display_name":"Ali A. Ghorbani","orcid":"https://orcid.org/0000-0001-9189-6268"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Ali A. Ghorbani","raw_affiliation_strings":["Faculty of Computer Science, UNB Fredericton, Canadian Institute for Cybersecurity (CIC), Canada"],"affiliations":[{"raw_affiliation_string":"Faculty of Computer Science, UNB Fredericton, Canadian Institute for Cybersecurity (CIC), Canada","institution_ids":[]}]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5039792020"],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.2719,"has_fulltext":false,"cited_by_count":2,"citation_normalized_percentile":{"value":0.6499276,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":94,"max":96},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"7"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9954000115394592,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9954000115394592,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11147","display_name":"Misinformation and Its Impacts","score":0.9909999966621399,"subfield":{"id":"https://openalex.org/subfields/3312","display_name":"Sociology and Political Science"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9797000288963318,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.8870775699615479},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8247160315513611},{"id":"https://openalex.org/keywords/black-box","display_name":"Black box","score":0.6697547435760498},{"id":"https://openalex.org/keywords/overhead","display_name":"Overhead (engineering)","score":0.6503746509552002},{"id":"https://openalex.org/keywords/domain","display_name":"Domain (mathematical analysis)","score":0.6343539953231812},{"id":"https://openalex.org/keywords/deep-neural-networks","display_name":"Deep neural networks","score":0.5536367893218994},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.524178683757782},{"id":"https://openalex.org/keywords/image","display_name":"Image (mathematics)","score":0.5235576033592224},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.521752655506134},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.5134537816047668},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.3783617317676544},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.3387943506240845},{"id":"https://openalex.org/keywords/information-retrieval","display_name":"Information retrieval","score":0.3362416625022888},{"id":"https://openalex.org/keywords/mathematics","display_name":"Mathematics","score":0.05855068564414978}],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.8870775699615479},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8247160315513611},{"id":"https://openalex.org/C94966114","wikidata":"https://www.wikidata.org/wiki/Q29256","display_name":"Black box","level":2,"score":0.6697547435760498},{"id":"https://openalex.org/C2779960059","wikidata":"https://www.wikidata.org/wiki/Q7113681","display_name":"Overhead (engineering)","level":2,"score":0.6503746509552002},{"id":"https://openalex.org/C36503486","wikidata":"https://www.wikidata.org/wiki/Q11235244","display_name":"Domain (mathematical analysis)","level":2,"score":0.6343539953231812},{"id":"https://openalex.org/C2984842247","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep neural networks","level":3,"score":0.5536367893218994},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.524178683757782},{"id":"https://openalex.org/C115961682","wikidata":"https://www.wikidata.org/wiki/Q860623","display_name":"Image (mathematics)","level":2,"score":0.5235576033592224},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.521752655506134},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.5134537816047668},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.3783617317676544},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.3387943506240845},{"id":"https://openalex.org/C23123220","wikidata":"https://www.wikidata.org/wiki/Q816826","display_name":"Information retrieval","level":1,"score":0.3362416625022888},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.05855068564414978},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.0},{"id":"https://openalex.org/C134306372","wikidata":"https://www.wikidata.org/wiki/Q7754","display_name":"Mathematical analysis","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/pst52912.2021.9647846","is_oa":false,"landing_page_url":"https://doi.org/10.1109/pst52912.2021.9647846","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2021 18th International Conference on Privacy, Security and Trust (PST)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16","score":0.7900000214576721}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":52,"referenced_works":["https://openalex.org/W1525595230","https://openalex.org/W1673923490","https://openalex.org/W1983873791","https://openalex.org/W2064675550","https://openalex.org/W2126583902","https://openalex.org/W2133286915","https://openalex.org/W2163455955","https://openalex.org/W2170240176","https://openalex.org/W2250539671","https://openalex.org/W2251295945","https://openalex.org/W2576546819","https://openalex.org/W2591788621","https://openalex.org/W2603766943","https://openalex.org/W2604505099","https://openalex.org/W2735135478","https://openalex.org/W2740811004","https://openalex.org/W2765424254","https://openalex.org/W2766108848","https://openalex.org/W2792059528","https://openalex.org/W2794557536","https://openalex.org/W2799194071","https://openalex.org/W2886412460","https://openalex.org/W2905526464","https://openalex.org/W2915238810","https://openalex.org/W2957482284","https://openalex.org/W2962718684","https://openalex.org/W2962818281","https://openalex.org/W2963062382","https://openalex.org/W2963245897","https://openalex.org/W2963834268","https://openalex.org/W2963859254","https://openalex.org/W2964232431","https://openalex.org/W2964301649","https://openalex.org/W2973226110","https://openalex.org/W2996851481","https://openalex.org/W3103557498","https://openalex.org/W3105833958","https://openalex.org/W4300511536","https://openalex.org/W6631501603","https://openalex.org/W6637162671","https://openalex.org/W6685053522","https://openalex.org/W6691640376","https://openalex.org/W6696511012","https://openalex.org/W6732414893","https://openalex.org/W6734028196","https://openalex.org/W6736789698","https://openalex.org/W6741419198","https://openalex.org/W6745847742","https://openalex.org/W6749879876","https://openalex.org/W6750404860","https://openalex.org/W6753792256","https://openalex.org/W6759682507"],"related_works":["https://openalex.org/W2950183588","https://openalex.org/W3080754722","https://openalex.org/W4383221314","https://openalex.org/W3093978547","https://openalex.org/W2953536436","https://openalex.org/W3203790781","https://openalex.org/W2997056298","https://openalex.org/W4313346231","https://openalex.org/W2738001131","https://openalex.org/W4377865163"],"abstract_inverted_index":{"Recent":[0],"work":[1],"has":[2],"demonstrated":[3],"that":[4,40,80,95,101],"modern":[5],"text":[6,24,56,78],"classifiers":[7],"trained":[8],"on":[9,23,63,77],"Deep":[10],"Neural":[11],"Networks":[12],"are":[13],"vulnerable":[14],"to":[15,28,82,117],"adversarial":[16,52,111],"attacks.":[17],"There":[18],"is":[19,105],"not":[20],"sufficient":[21],"study":[22],"data":[25,79],"in":[26,43,54],"comparison":[27],"the":[29,38,44,55,59,64,91,102,109,118,127],"image":[30],"domain.":[31,46],"The":[32,121],"lack":[33],"of":[34,93,123],"investigation":[35],"originates":[36],"from":[37],"challenges":[39],"authors":[41],"confront":[42],"NLP":[45],"Despite":[47],"being":[48],"extremely":[49],"prosperous,":[50],"most":[51],"attacks":[53,112],"domain":[57],"ignore":[58],"overhead":[60,94],"they":[61],"induced":[62],"victim":[65,119],"model.":[66,120],"In":[67],"this":[68],"paper,":[69],"we":[70],"propose":[71],"a":[72,84],"Query-efficient":[73],"Black-box":[74],"Adversarial":[75],"Attack":[76],"tries":[81],"attack":[83,104],"textual":[85],"deep":[86],"neural":[87],"network":[88],"by":[89],"considering":[90],"amount":[92],"it":[96],"may":[97],"produce.":[98],"We":[99],"show":[100],"proposed":[103],"as":[106,108],"powerful":[107],"state-of-the-art":[110],"while":[113],"requiring":[114],"fewer":[115],"queries":[116],"evaluation":[122],"our":[124],"method":[125],"proves":[126],"promising":[128],"results.":[129]},"counts_by_year":[{"year":2024,"cited_by_count":2}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
