{"id":"https://openalex.org/W3212790025","doi":"https://doi.org/10.1109/tpami.2021.3126733","title":"Query-Efficient Black-Box Adversarial Attacks Guided by a Transfer-Based Prior","display_name":"Query-Efficient Black-Box Adversarial Attacks Guided by a Transfer-Based Prior","publication_year":2021,"publication_date":"2021-11-09","ids":{"openalex":"https://openalex.org/W3212790025","doi":"https://doi.org/10.1109/tpami.2021.3126733","mag":"3212790025","pmid":"https://pubmed.ncbi.nlm.nih.gov/34752388"},"language":"en","primary_location":{"id":"doi:10.1109/tpami.2021.3126733","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tpami.2021.3126733","pdf_url":null,"source":{"id":"https://openalex.org/S199944782","display_name":"IEEE Transactions on Pattern Analysis and Machine Intelligence","issn_l":"0162-8828","issn":["0162-8828","1939-3539","2160-9292"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320439","host_organization_name":"IEEE Computer Society","host_organization_lineage":["https://openalex.org/P4310320439","https://openalex.org/P4310319808"],"host_organization_lineage_names":["IEEE Computer Society","Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Pattern Analysis and Machine Intelligence","raw_type":"journal-article"},"type":"article","indexed_in":["crossref","pubmed"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":null,"display_name":"Yinpeng Dong","orcid":"https://orcid.org/0000-0003-1299-683X"},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Yinpeng Dong","raw_affiliation_strings":["Department of Computer Science and Technology, Beijing National Research Center for Information Science and Technology, Tsinghua-Bosch Joint Center for Machine Learning, Institute for Artificial Intelligence, Tsinghua University, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science and Technology, Beijing National Research Center for Information Science and Technology, Tsinghua-Bosch Joint Center for Machine Learning, Institute for Artificial Intelligence, Tsinghua University, Beijing, China","institution_ids":["https://openalex.org/I99065089"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Shuyu Cheng","orcid":null},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Shuyu Cheng","raw_affiliation_strings":["Department of Computer Science and Technology, Beijing National Research Center for Information Science and Technology, Tsinghua-Bosch Joint Center for Machine Learning, Institute for Artificial Intelligence, Tsinghua University, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science and Technology, Beijing National Research Center for Information Science and Technology, Tsinghua-Bosch Joint Center for Machine Learning, Institute for Artificial Intelligence, Tsinghua University, Beijing, China","institution_ids":["https://openalex.org/I99065089"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Tianyu Pang","orcid":"https://orcid.org/0000-0003-0639-6176"},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Tianyu Pang","raw_affiliation_strings":["Department of Computer Science and Technology, Beijing National Research Center for Information Science and Technology, Tsinghua-Bosch Joint Center for Machine Learning, Institute for Artificial Intelligence, Tsinghua University, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science and Technology, Beijing National Research Center for Information Science and Technology, Tsinghua-Bosch Joint Center for Machine Learning, Institute for Artificial Intelligence, Tsinghua University, Beijing, China","institution_ids":["https://openalex.org/I99065089"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Hang Su","orcid":null},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Hang Su","raw_affiliation_strings":["Department of Computer Science and Technology, Beijing National Research Center for Information Science and Technology, Tsinghua-Bosch Joint Center for Machine Learning, Institute for Artificial Intelligence, Tsinghua University, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science and Technology, Beijing National Research Center for Information Science and Technology, Tsinghua-Bosch Joint Center for Machine Learning, Institute for Artificial Intelligence, Tsinghua University, Beijing, China","institution_ids":["https://openalex.org/I99065089"]}]},{"author_position":"last","author":{"id":null,"display_name":"Jun Zhu","orcid":null},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Jun Zhu","raw_affiliation_strings":["Department of Computer Science and Technology, Beijing National Research Center for Information Science and Technology, Tsinghua-Bosch Joint Center for Machine Learning, Institute for Artificial Intelligence, Tsinghua University, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science and Technology, Beijing National Research Center for Information Science and Technology, Tsinghua-Bosch Joint Center for Machine Learning, Institute for Artificial Intelligence, Tsinghua University, Beijing, China","institution_ids":["https://openalex.org/I99065089"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":[],"corresponding_institution_ids":["https://openalex.org/I99065089"],"apc_list":null,"apc_paid":null,"fwci":4.4788,"has_fulltext":false,"cited_by_count":49,"citation_normalized_percentile":{"value":0.954211,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":96,"max":100},"biblio":{"volume":"44","issue":"12","first_page":"9536","last_page":"9548"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9890999794006348,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9890999794006348,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.001500000013038516,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11612","display_name":"Stochastic Gradient Optimization Techniques","score":0.0010000000474974513,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.8341000080108643},{"id":"https://openalex.org/keywords/adversary","display_name":"Adversary","score":0.5005000233650208},{"id":"https://openalex.org/keywords/sampling","display_name":"Sampling (signal processing)","score":0.39089998602867126},{"id":"https://openalex.org/keywords/adversarial-machine-learning","display_name":"Adversarial machine learning","score":0.3880999982357025},{"id":"https://openalex.org/keywords/vulnerability","display_name":"Vulnerability (computing)","score":0.3499999940395355},{"id":"https://openalex.org/keywords/gradient-descent","display_name":"Gradient descent","score":0.34880000352859497}],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.8341000080108643},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7583000063896179},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5608000159263611},{"id":"https://openalex.org/C41065033","wikidata":"https://www.wikidata.org/wiki/Q2825412","display_name":"Adversary","level":2,"score":0.5005000233650208},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.4569000005722046},{"id":"https://openalex.org/C140779682","wikidata":"https://www.wikidata.org/wiki/Q210868","display_name":"Sampling (signal processing)","level":3,"score":0.39089998602867126},{"id":"https://openalex.org/C2778403875","wikidata":"https://www.wikidata.org/wiki/Q20312394","display_name":"Adversarial machine learning","level":3,"score":0.3880999982357025},{"id":"https://openalex.org/C95713431","wikidata":"https://www.wikidata.org/wiki/Q631425","display_name":"Vulnerability (computing)","level":2,"score":0.3499999940395355},{"id":"https://openalex.org/C153258448","wikidata":"https://www.wikidata.org/wiki/Q1199743","display_name":"Gradient descent","level":3,"score":0.34880000352859497},{"id":"https://openalex.org/C115680565","wikidata":"https://www.wikidata.org/wiki/Q5977448","display_name":"Gradient method","level":2,"score":0.3411000072956085},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.3407000005245209},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.3294000029563904},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.3264000117778778},{"id":"https://openalex.org/C206688291","wikidata":"https://www.wikidata.org/wiki/Q7617819","display_name":"Stochastic gradient descent","level":3,"score":0.2703999876976013},{"id":"https://openalex.org/C126255220","wikidata":"https://www.wikidata.org/wiki/Q141495","display_name":"Mathematical optimization","level":1,"score":0.2565999925136566},{"id":"https://openalex.org/C150899416","wikidata":"https://www.wikidata.org/wiki/Q1820378","display_name":"Transfer of learning","level":2,"score":0.25450000166893005}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1109/tpami.2021.3126733","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tpami.2021.3126733","pdf_url":null,"source":{"id":"https://openalex.org/S199944782","display_name":"IEEE Transactions on Pattern Analysis and Machine Intelligence","issn_l":"0162-8828","issn":["0162-8828","1939-3539","2160-9292"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320439","host_organization_name":"IEEE Computer Society","host_organization_lineage":["https://openalex.org/P4310320439","https://openalex.org/P4310319808"],"host_organization_lineage_names":["IEEE Computer Society","Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Pattern Analysis and Machine Intelligence","raw_type":"journal-article"},{"id":"pmid:34752388","is_oa":false,"landing_page_url":"https://pubmed.ncbi.nlm.nih.gov/34752388","pdf_url":null,"source":{"id":"https://openalex.org/S4306525036","display_name":"PubMed","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I1299303238","host_organization_name":"National Institutes of Health","host_organization_lineage":["https://openalex.org/I1299303238"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE transactions on pattern analysis and machine intelligence","raw_type":null}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":45,"referenced_works":["https://openalex.org/W2117539524","https://openalex.org/W2149479912","https://openalex.org/W2171830216","https://openalex.org/W2183341477","https://openalex.org/W2194775991","https://openalex.org/W2302255633","https://openalex.org/W2603766943","https://openalex.org/W2746600820","https://openalex.org/W2752782242","https://openalex.org/W2774644650","https://openalex.org/W2887603965","https://openalex.org/W2895097814","https://openalex.org/W2906208681","https://openalex.org/W2962847335","https://openalex.org/W2963470657","https://openalex.org/W2963857521","https://openalex.org/W2964205597","https://openalex.org/W2964350391","https://openalex.org/W2969542116","https://openalex.org/W2972986629","https://openalex.org/W3034214559","https://openalex.org/W3103836116","https://openalex.org/W4254631372","https://openalex.org/W6637162671","https://openalex.org/W6637373629","https://openalex.org/W6640425456","https://openalex.org/W6682262322","https://openalex.org/W6713132643","https://openalex.org/W6714069269","https://openalex.org/W6719080892","https://openalex.org/W6725739302","https://openalex.org/W6731927902","https://openalex.org/W6739868092","https://openalex.org/W6746608116","https://openalex.org/W6747536865","https://openalex.org/W6748475379","https://openalex.org/W6749023905","https://openalex.org/W6750404860","https://openalex.org/W6753044988","https://openalex.org/W6755233895","https://openalex.org/W6761833289","https://openalex.org/W6762760680","https://openalex.org/W6764550947","https://openalex.org/W6783646676","https://openalex.org/W6787972765"],"related_works":[],"abstract_inverted_index":{"Adversarial":[0],"attacks":[1],"have":[2],"been":[3],"extensively":[4],"studied":[5],"in":[6,97,168,175],"recent":[7],"years":[8],"since":[9,89],"they":[10],"can":[11,131],"identify":[12],"the":[13,26,31,41,52,58,69,75,95,133,141,148,155,178],"vulnerability":[14],"of":[15,43,61,71,135,143,182],"deep":[16],"learning":[17],"models":[18,192],"before":[19],"deployed.":[20],"In":[21],"this":[22],"paper,":[23],"we":[24,113],"consider":[25],"black-box":[27,111,191],"adversarial":[28,36],"setting,":[29],"where":[30],"adversary":[32],"needs":[33],"to":[34,40,50,93,189],"craft":[35],"examples":[37],"without":[38],"access":[39],"gradients":[42],"a":[44,62,98,136,144],"target":[45],"model.":[46],"Previous":[47],"methods":[48,77,130,184],"attempted":[49],"approximate":[51],"true":[53],"gradient":[54,60,96,126,142],"either":[55],"by":[56,140,164],"using":[57],"transfer":[59],"surrogate":[63,145],"white-box":[64],"model":[65,72,146,162],"or":[66,85],"based":[67,121],"on":[68,122],"feedback":[70],"queries.":[73],"However,":[74],"existing":[76],"inevitably":[78],"suffer":[79],"from":[80],"low":[81],"attack":[82,190],"success":[83,195],"rates":[84],"poor":[86],"query":[87,149],"efficiency":[88],"it":[90],"is":[91,158],"difficult":[92],"estimate":[94],"high-dimensional":[99],"input":[100],"space":[101],"with":[102,161,177,193],"limited":[103],"information.":[104],"To":[105],"address":[106],"these":[107],"problems":[108],"and":[109,125,147],"improve":[110],"attacks,":[112],"propose":[114],"two":[115],"prior-guided":[116],"random":[117],"gradient-free":[118],"(PRGF)":[119],"algorithms":[120],"biased":[123],"sampling":[124],"averaging,":[127],"respectively.":[128],"Our":[129],"take":[132],"advantage":[134],"transfer-based":[137,156],"prior":[138,157],"given":[139],"information":[150],"simultaneously.":[151],"Through":[152],"theoretical":[153],"analyses,":[154],"appropriately":[159],"integrated":[160],"queries":[163,188],"an":[165],"optimal":[166],"coefficient":[167],"each":[169],"method.":[170],"Extensive":[171],"experiments":[172],"demonstrate":[173],"that,":[174],"comparison":[176],"alternative":[179],"state-of-the-arts,":[180],"both":[181],"our":[183],"require":[185],"much":[186],"fewer":[187],"higher":[194],"rates.":[196]},"counts_by_year":[{"year":2026,"cited_by_count":2},{"year":2025,"cited_by_count":15},{"year":2024,"cited_by_count":20},{"year":2023,"cited_by_count":9},{"year":2022,"cited_by_count":3}],"updated_date":"2026-03-27T05:58:40.876381","created_date":"2021-11-22T00:00:00"}
