{"id":"https://openalex.org/W2890324916","doi":"https://doi.org/10.1145/3270101.3270106","title":"Towards Query Efficient Black-box Attacks","display_name":"Towards Query Efficient Black-box Attacks","publication_year":2018,"publication_date":"2018-01-15","ids":{"openalex":"https://openalex.org/W2890324916","doi":"https://doi.org/10.1145/3270101.3270106","mag":"2890324916"},"language":"en","primary_location":{"id":"doi:10.1145/3270101.3270106","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3270101.3270106","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 11th ACM Workshop on Artificial Intelligence and Security","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5002080576","display_name":"Yali Du","orcid":"https://orcid.org/0000-0001-5683-2621"},"institutions":[{"id":"https://openalex.org/I114017466","display_name":"University of Technology Sydney","ror":"https://ror.org/03f0f6041","country_code":"AU","type":"education","lineage":["https://openalex.org/I114017466"]}],"countries":["AU"],"is_corresponding":true,"raw_author_name":"Yali Du","raw_affiliation_strings":["University of Technology Sydney &amp; Shenzhen Institutes of Advanced Technology, CAS, Sydney, Australia"],"affiliations":[{"raw_affiliation_string":"University of Technology Sydney &amp; Shenzhen Institutes of Advanced Technology, CAS, Sydney, Australia","institution_ids":["https://openalex.org/I114017466"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100400497","display_name":"Meng Fang","orcid":"https://orcid.org/0000-0003-0793-9187"},"institutions":[{"id":"https://openalex.org/I2250653659","display_name":"Tencent (China)","ror":"https://ror.org/00hhjss72","country_code":"CN","type":"company","lineage":["https://openalex.org/I2250653659"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Meng Fang","raw_affiliation_strings":["Tencent AI Lab, Shenzhen, China"],"affiliations":[{"raw_affiliation_string":"Tencent AI Lab, Shenzhen, China","institution_ids":["https://openalex.org/I2250653659"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5030837133","display_name":"Jinfeng Yi","orcid":"https://orcid.org/0000-0003-2149-0670"},"institutions":[{"id":"https://openalex.org/I4210103986","display_name":"Jingdong (China)","ror":"https://ror.org/01dkjkq64","country_code":"CN","type":"company","lineage":["https://openalex.org/I4210103986"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Jinfeng Yi","raw_affiliation_strings":["JD AI Research, Beijing, China"],"affiliations":[{"raw_affiliation_string":"JD AI Research, Beijing, China","institution_ids":["https://openalex.org/I4210103986"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101705358","display_name":"Jun Cheng","orcid":"https://orcid.org/0000-0002-3131-3275"},"institutions":[{"id":"https://openalex.org/I4210116924","display_name":"Chinese University of Hong Kong, Shenzhen","ror":"https://ror.org/02d5ks197","country_code":"CN","type":"education","lineage":["https://openalex.org/I177725633","https://openalex.org/I180726961","https://openalex.org/I4210116924"]},{"id":"https://openalex.org/I4210145761","display_name":"Shenzhen Institutes of Advanced Technology","ror":"https://ror.org/04gh4er46","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210145761"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Jun Cheng","raw_affiliation_strings":["Shenzhen Institutes of Advanced Technology, CAS &amp; Chinese University of Hong Kong, Shenzhen, China"],"affiliations":[{"raw_affiliation_string":"Shenzhen Institutes of Advanced Technology, CAS &amp; Chinese University of Hong Kong, Shenzhen, China","institution_ids":["https://openalex.org/I4210145761","https://openalex.org/I4210116924"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5074103823","display_name":"Dacheng Tao","orcid":"https://orcid.org/0000-0001-7225-5449"},"institutions":[{"id":"https://openalex.org/I129604602","display_name":"University of Sydney","ror":"https://ror.org/0384j8v12","country_code":"AU","type":"education","lineage":["https://openalex.org/I129604602"]}],"countries":["AU"],"is_corresponding":false,"raw_author_name":"Dacheng Tao","raw_affiliation_strings":["University of Sydney, Sydney, Australia"],"affiliations":[{"raw_affiliation_string":"University of Sydney, Sydney, Australia","institution_ids":["https://openalex.org/I129604602"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5002080576"],"corresponding_institution_ids":["https://openalex.org/I114017466"],"apc_list":null,"apc_paid":null,"fwci":1.1401,"has_fulltext":false,"cited_by_count":16,"citation_normalized_percentile":{"value":0.83844318,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"13","last_page":"24"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11307","display_name":"Domain Adaptation and Few-Shot Learning","score":0.9473000168800354,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10036","display_name":"Advanced Neural Network Applications","score":0.9330999851226807,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7865198850631714},{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.751150369644165},{"id":"https://openalex.org/keywords/deep-neural-networks","display_name":"Deep neural networks","score":0.6482089161872864},{"id":"https://openalex.org/keywords/black-box","display_name":"Black box","score":0.642421305179596},{"id":"https://openalex.org/keywords/image","display_name":"Image (mathematics)","score":0.5336967706680298},{"id":"https://openalex.org/keywords/adversary","display_name":"Adversary","score":0.47483521699905396},{"id":"https://openalex.org/keywords/dimension","display_name":"Dimension (graph theory)","score":0.4741981625556946},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.4471568465232849},{"id":"https://openalex.org/keywords/threat-model","display_name":"Threat model","score":0.4276665449142456},{"id":"https://openalex.org/keywords/pixel","display_name":"Pixel","score":0.4218616187572479},{"id":"https://openalex.org/keywords/heuristic","display_name":"Heuristic","score":0.42043134570121765},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.41658130288124084},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.4147852063179016},{"id":"https://openalex.org/keywords/theoretical-computer-science","display_name":"Theoretical computer science","score":0.3630344867706299},{"id":"https://openalex.org/keywords/algorithm","display_name":"Algorithm","score":0.3252337574958801},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.16469597816467285},{"id":"https://openalex.org/keywords/mathematics","display_name":"Mathematics","score":0.11327105760574341}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7865198850631714},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.751150369644165},{"id":"https://openalex.org/C2984842247","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep neural networks","level":3,"score":0.6482089161872864},{"id":"https://openalex.org/C94966114","wikidata":"https://www.wikidata.org/wiki/Q29256","display_name":"Black box","level":2,"score":0.642421305179596},{"id":"https://openalex.org/C115961682","wikidata":"https://www.wikidata.org/wiki/Q860623","display_name":"Image (mathematics)","level":2,"score":0.5336967706680298},{"id":"https://openalex.org/C41065033","wikidata":"https://www.wikidata.org/wiki/Q2825412","display_name":"Adversary","level":2,"score":0.47483521699905396},{"id":"https://openalex.org/C33676613","wikidata":"https://www.wikidata.org/wiki/Q13415176","display_name":"Dimension (graph theory)","level":2,"score":0.4741981625556946},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.4471568465232849},{"id":"https://openalex.org/C140547941","wikidata":"https://www.wikidata.org/wiki/Q7797194","display_name":"Threat model","level":2,"score":0.4276665449142456},{"id":"https://openalex.org/C160633673","wikidata":"https://www.wikidata.org/wiki/Q355198","display_name":"Pixel","level":2,"score":0.4218616187572479},{"id":"https://openalex.org/C173801870","wikidata":"https://www.wikidata.org/wiki/Q201413","display_name":"Heuristic","level":2,"score":0.42043134570121765},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.41658130288124084},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.4147852063179016},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.3630344867706299},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.3252337574958801},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.16469597816467285},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.11327105760574341},{"id":"https://openalex.org/C202444582","wikidata":"https://www.wikidata.org/wiki/Q837863","display_name":"Pure mathematics","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3270101.3270106","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3270101.3270106","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 11th ACM Workshop on Artificial Intelligence and Security","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"score":0.41999998688697815,"id":"https://metadata.un.org/sdg/16","display_name":"Peace, Justice and strong institutions"}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":24,"referenced_works":["https://openalex.org/W1932198206","https://openalex.org/W1945616565","https://openalex.org/W2108598243","https://openalex.org/W2117539524","https://openalex.org/W2125908420","https://openalex.org/W2151298633","https://openalex.org/W2151965738","https://openalex.org/W2180612164","https://openalex.org/W2183341477","https://openalex.org/W2243397390","https://openalex.org/W2570685808","https://openalex.org/W2596367596","https://openalex.org/W2603766943","https://openalex.org/W2746600820","https://openalex.org/W2773726006","https://openalex.org/W2774644650","https://openalex.org/W2953384591","https://openalex.org/W2963070423","https://openalex.org/W2963857521","https://openalex.org/W2964153729","https://openalex.org/W2964205597","https://openalex.org/W2964253222","https://openalex.org/W3007384386","https://openalex.org/W3106412272"],"related_works":["https://openalex.org/W4320018150","https://openalex.org/W2040808657","https://openalex.org/W4239582170","https://openalex.org/W2918664383","https://openalex.org/W106056076","https://openalex.org/W4320855730","https://openalex.org/W2135200719","https://openalex.org/W2950183588","https://openalex.org/W3080754722","https://openalex.org/W4383221314"],"abstract_inverted_index":{"Recent":[0,201],"studies":[1,202],"have":[2,203],"highlighted":[3,204],"that":[4,58,205,259,407],"deep":[5,206],"neural":[6,207],"networks":[7,208],"(DNNs)":[8,209],"are":[9,210],"vulnerable":[10,211],"to":[11,28,35,64,68,88,105,111,124,171,212,229,236,265,269,289,306,312,325,372,420],"adversarial":[12,60,77,134,213,261,278,335],"attacks,":[13,37,214,238],"even":[14,215],"in":[15,42,73,216,243,274],"a":[16,30,90,137,165,184,194,217,231,291,338,366,385,395,417,427],"black-box":[17,24,218,225],"scenario.":[18,219],"However,":[19,220],"most":[20,221],"of":[21,33,49,159,222,234,250,360,424],"the":[22,43,50,54,59,69,127,147,151,157,160,173,223,244,251,255,260,270,328,348,352,358,361,374,442,448],"existing":[23,224],"attack":[25,92,161,226,293,362],"algorithms":[26,227],"need":[27,228],"make":[29,177,230,378],"huge":[31,232],"amount":[32,233],"queries":[34,56,235,257,411],"perform":[36,237],"which":[38,97,142,239,298,343],"is":[39,57,62,109,240,258,263,310],"not":[40,82,241,283],"practical":[41,242],"real":[44,245],"world.":[45,246],"We":[46,247],"note":[47,248],"one":[48,249],"main":[51,252],"reasons":[52,253],"for":[53,150,197,254,351,398],"massive":[55,256],"example":[61,135,262,336],"required":[63,264],"be":[65,266],"visually":[66,267],"similar":[67,268],"original":[70,271],"image,":[71,272],"but":[72,273],"many":[74,275],"cases,":[75,276],"how":[76,277],"examples":[78,279],"look":[79,280],"like":[80,281],"does":[81,282],"matter":[83,284],"much.":[84,285],"It":[85,286],"inspires":[86,287],"us":[87,288],"introduce":[89,290],"new":[91,292],"called":[93,294],"input-free":[94,295],"attack,":[95,296],"under":[96,297],"an":[98,102,133,299,303,334],"adversary":[99,300],"can":[100,301,415],"choose":[101,302],"arbitrary":[103,304],"image":[104,140,305,341,419],"start":[106,307],"with":[107,136,189,308,337,390,408,426],"and":[108,168,191,309,369,392,447],"allowed":[110,311],"add":[112,313],"perceptible":[113,314],"perturbations":[114,315],"on":[115,141,316,342,412,431],"it.":[116,317],"Following":[117,318],"this":[118,319],"approach,":[119,320],"we":[120,131,155,182,321,332,356,383,405,414],"propose":[121,193,322,394],"two":[122,323,439],"techniques":[123,324],"significantly":[125,326],"reduce":[126,327],"query":[128,329],"complexity.":[129,330],"First,":[130,331],"initialize":[132,333],"gray":[138,339,418],"color":[139,340],"every":[143,344],"pixel":[144,345],"has":[145,346,436],"roughly":[146,347],"same":[148,349],"importance":[149,350],"target":[152,353,422],"model.":[153,354],"Then":[154,355],"shrink":[156,357],"dimension":[158,359],"space":[162,363],"by":[163,364],"perturbing":[164,365],"small":[166,367],"region":[167,198,368,399],"tiling":[169,370],"it":[170,371],"cover":[172,373],"input":[174,375],"image.":[175,376],"To":[176,377],"our":[178,379,434],"algorithm":[179,188,380,389,435],"more":[180,381],"effective,":[181,382],"stabilize":[183,384],"projected":[185,386],"gradient":[186,387],"ascent":[187,388],"momentum,":[190,391],"also":[192,393],"heuristic":[195,396],"approach":[196,397],"size":[199,400],"selection.":[200,401],"Through":[402],"extensive":[403],"experiments,":[404],"show":[406],"only":[409],"1,701":[410],"average,":[413],"perturb":[416],"any":[421],"class":[423],"ImageNet":[425],"100%":[428],"success":[429],"rate":[430],"InceptionV3.":[432],"Besides,":[433],"successfully":[437],"defeated":[438],"real-world":[440],"systems,":[441],"Clarifai":[443],"food":[444],"detection":[445],"API":[446],"Baidu":[449],"Animal":[450],"Identification":[451],"API.":[452]},"counts_by_year":[{"year":2025,"cited_by_count":1},{"year":2024,"cited_by_count":2},{"year":2023,"cited_by_count":2},{"year":2022,"cited_by_count":4},{"year":2021,"cited_by_count":1},{"year":2019,"cited_by_count":6}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
