{"id":"https://openalex.org/W2982109374","doi":"https://doi.org/10.1145/3343031.3351088","title":"Black-box Adversarial Attacks on Video Recognition Models","display_name":"Black-box Adversarial Attacks on Video Recognition Models","publication_year":2019,"publication_date":"2019-10-15","ids":{"openalex":"https://openalex.org/W2982109374","doi":"https://doi.org/10.1145/3343031.3351088","mag":"2982109374"},"language":"en","primary_location":{"id":"doi:10.1145/3343031.3351088","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3343031.3351088","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 27th ACM International Conference on Multimedia","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5029860118","display_name":"Linxi Jiang","orcid":null},"institutions":[{"id":"https://openalex.org/I24943067","display_name":"Fudan University","ror":"https://ror.org/013q1eq08","country_code":"CN","type":"education","lineage":["https://openalex.org/I24943067"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Linxi Jiang","raw_affiliation_strings":["Fudan University, Shanghai, China"],"affiliations":[{"raw_affiliation_string":"Fudan University, Shanghai, China","institution_ids":["https://openalex.org/I24943067"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5078711649","display_name":"Xingjun Ma","orcid":"https://orcid.org/0000-0003-2099-4973"},"institutions":[{"id":"https://openalex.org/I165779595","display_name":"University of Melbourne","ror":"https://ror.org/01ej9dk98","country_code":"AU","type":"education","lineage":["https://openalex.org/I165779595"]}],"countries":["AU"],"is_corresponding":false,"raw_author_name":"Xingjun Ma","raw_affiliation_strings":["The University of Melbourne, Melbourne, Australia"],"affiliations":[{"raw_affiliation_string":"The University of Melbourne, Melbourne, Australia","institution_ids":["https://openalex.org/I165779595"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101499520","display_name":"Shaoxiang Chen","orcid":"https://orcid.org/0000-0002-7627-7124"},"institutions":[{"id":"https://openalex.org/I24943067","display_name":"Fudan University","ror":"https://ror.org/013q1eq08","country_code":"CN","type":"education","lineage":["https://openalex.org/I24943067"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Shaoxiang Chen","raw_affiliation_strings":["Fudan University, Shanghai, China"],"affiliations":[{"raw_affiliation_string":"Fudan University, Shanghai, China","institution_ids":["https://openalex.org/I24943067"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101609697","display_name":"James Bailey","orcid":"https://orcid.org/0000-0002-3769-3811"},"institutions":[{"id":"https://openalex.org/I165779595","display_name":"University of Melbourne","ror":"https://ror.org/01ej9dk98","country_code":"AU","type":"education","lineage":["https://openalex.org/I165779595"]}],"countries":["AU"],"is_corresponding":false,"raw_author_name":"James Bailey","raw_affiliation_strings":["The University of Melbourne, Melbourne, Australia"],"affiliations":[{"raw_affiliation_string":"The University of Melbourne, Melbourne, Australia","institution_ids":["https://openalex.org/I165779595"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5047962986","display_name":"Yu\u2013Gang Jiang","orcid":"https://orcid.org/0000-0002-1907-8567"},"institutions":[{"id":"https://openalex.org/I24943067","display_name":"Fudan University","ror":"https://ror.org/013q1eq08","country_code":"CN","type":"education","lineage":["https://openalex.org/I24943067"]},{"id":"https://openalex.org/I4210099297","display_name":"Jilian Technology Group (China)","ror":"https://ror.org/016q5ce10","country_code":"CN","type":"company","lineage":["https://openalex.org/I4210099297"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yu-Gang Jiang","raw_affiliation_strings":["Fudan University and Jilian Technology Group, Shanghai, China"],"affiliations":[{"raw_affiliation_string":"Fudan University and Jilian Technology Group, Shanghai, China","institution_ids":["https://openalex.org/I4210099297","https://openalex.org/I24943067"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5029860118"],"corresponding_institution_ids":["https://openalex.org/I24943067"],"apc_list":null,"apc_paid":null,"fwci":11.9947,"has_fulltext":false,"cited_by_count":147,"citation_normalized_percentile":{"value":0.98815371,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":94,"max":100},"biblio":{"volume":null,"issue":null,"first_page":"864","last_page":"872"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9761000275611877,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11307","display_name":"Domain Adaptation and Few-Shot Learning","score":0.920199990272522,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7738226652145386},{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.7569116353988647},{"id":"https://openalex.org/keywords/black-box","display_name":"Black box","score":0.666014552116394},{"id":"https://openalex.org/keywords/benchmark","display_name":"Benchmark (surveying)","score":0.6112684607505798},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.5427139401435852},{"id":"https://openalex.org/keywords/subspace-topology","display_name":"Subspace topology","score":0.5340937972068787},{"id":"https://openalex.org/keywords/image","display_name":"Image (mathematics)","score":0.5335899591445923},{"id":"https://openalex.org/keywords/deep-neural-networks","display_name":"Deep neural networks","score":0.5038980841636658},{"id":"https://openalex.org/keywords/adversary","display_name":"Adversary","score":0.48839038610458374},{"id":"https://openalex.org/keywords/vulnerability","display_name":"Vulnerability (computing)","score":0.47103574872016907},{"id":"https://openalex.org/keywords/projection","display_name":"Projection (relational algebra)","score":0.4155597388744354},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.3930662274360657},{"id":"https://openalex.org/keywords/pattern-recognition","display_name":"Pattern recognition (psychology)","score":0.36813902854919434},{"id":"https://openalex.org/keywords/algorithm","display_name":"Algorithm","score":0.1981140375137329},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.1574302613735199}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7738226652145386},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.7569116353988647},{"id":"https://openalex.org/C94966114","wikidata":"https://www.wikidata.org/wiki/Q29256","display_name":"Black box","level":2,"score":0.666014552116394},{"id":"https://openalex.org/C185798385","wikidata":"https://www.wikidata.org/wiki/Q1161707","display_name":"Benchmark (surveying)","level":2,"score":0.6112684607505798},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5427139401435852},{"id":"https://openalex.org/C32834561","wikidata":"https://www.wikidata.org/wiki/Q660730","display_name":"Subspace topology","level":2,"score":0.5340937972068787},{"id":"https://openalex.org/C115961682","wikidata":"https://www.wikidata.org/wiki/Q860623","display_name":"Image (mathematics)","level":2,"score":0.5335899591445923},{"id":"https://openalex.org/C2984842247","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep neural networks","level":3,"score":0.5038980841636658},{"id":"https://openalex.org/C41065033","wikidata":"https://www.wikidata.org/wiki/Q2825412","display_name":"Adversary","level":2,"score":0.48839038610458374},{"id":"https://openalex.org/C95713431","wikidata":"https://www.wikidata.org/wiki/Q631425","display_name":"Vulnerability (computing)","level":2,"score":0.47103574872016907},{"id":"https://openalex.org/C57493831","wikidata":"https://www.wikidata.org/wiki/Q3134666","display_name":"Projection (relational algebra)","level":2,"score":0.4155597388744354},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.3930662274360657},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.36813902854919434},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.1981140375137329},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.1574302613735199},{"id":"https://openalex.org/C13280743","wikidata":"https://www.wikidata.org/wiki/Q131089","display_name":"Geodesy","level":1,"score":0.0},{"id":"https://openalex.org/C205649164","wikidata":"https://www.wikidata.org/wiki/Q1071","display_name":"Geography","level":0,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3343031.3351088","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3343031.3351088","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 27th ACM International Conference on Multimedia","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"score":0.6299999952316284,"id":"https://metadata.un.org/sdg/16","display_name":"Peace, Justice and strong institutions"}],"awards":[{"id":"https://openalex.org/G1121271761","display_name":null,"funder_award_id":"Program","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G1231421488","display_name":null,"funder_award_id":"under","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G2087396116","display_name":null,"funder_award_id":"China","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G3294234326","display_name":null,"funder_award_id":"2018YFB1004","funder_id":"https://openalex.org/F4320335777","funder_display_name":"National Key Research and Development Program of China"},{"id":"https://openalex.org/G3317480652","display_name":null,"funder_award_id":"Science","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G383754086","display_name":null,"funder_award_id":"2018YFB1004300","funder_id":"https://openalex.org/F4320335777","funder_display_name":"National Key Research and Development Program of China"},{"id":"https://openalex.org/G5848258319","display_name":null,"funder_award_id":"0 and","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G585447023","display_name":null,"funder_award_id":"61622204","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G5994120800","display_name":null,"funder_award_id":"Natural","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"}],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"},{"id":"https://openalex.org/F4320335777","display_name":"National Key Research and Development Program of China","ror":null}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":32,"referenced_works":["https://openalex.org/W1777628566","https://openalex.org/W1923404803","https://openalex.org/W1932198206","https://openalex.org/W1983364832","https://openalex.org/W2016053056","https://openalex.org/W2126579184","https://openalex.org/W2154579312","https://openalex.org/W2180612164","https://openalex.org/W2243397390","https://openalex.org/W2526479943","https://openalex.org/W2543927648","https://openalex.org/W2603766943","https://openalex.org/W2746600820","https://openalex.org/W2765823242","https://openalex.org/W2766520430","https://openalex.org/W2787708942","https://openalex.org/W2798302089","https://openalex.org/W2895097814","https://openalex.org/W2895845501","https://openalex.org/W2945793108","https://openalex.org/W2963062382","https://openalex.org/W2963158386","https://openalex.org/W2963207607","https://openalex.org/W2963524571","https://openalex.org/W2963612069","https://openalex.org/W2963857521","https://openalex.org/W2964045146","https://openalex.org/W2964116600","https://openalex.org/W2964153729","https://openalex.org/W2964253222","https://openalex.org/W3007384386","https://openalex.org/W3106412272"],"related_works":["https://openalex.org/W4320018150","https://openalex.org/W4239582170","https://openalex.org/W2918664383","https://openalex.org/W106056076","https://openalex.org/W4320855730","https://openalex.org/W2135200719","https://openalex.org/W2950183588","https://openalex.org/W3080754722","https://openalex.org/W3093978547","https://openalex.org/W2953536436"],"abstract_inverted_index":{"Deep":[0],"neural":[1],"networks":[2],"(DNNs)":[3],"are":[4,13,92],"known":[5],"for":[6,75,86],"their":[7],"vulnerability":[8],"to":[9,59,122,131,138,166,199,231,241],"adversarial":[10,40,125,144,243],"examples.":[11],"These":[12],"examples":[14],"that":[15,157,209,224],"have":[16,83,212],"undergone":[17],"small,":[18],"carefully":[19],"crafted":[20],"perturbations,":[21],"and":[22,163,233],"which":[23],"can":[24,69,159],"easily":[25],"fool":[26,167],"a":[27,50,63,147,194,227],"DNN":[28],"into":[29],"making":[30],"misclassifications":[31],"at":[32],"test":[33],"time.":[34],"Thus":[35],"far,":[36],"the":[37,72,101,120,132,140,143,175,207,235],"field":[38],"of":[39,142,187,197,215,237],"research":[41],"has":[42,56],"mainly":[43],"focused":[44],"on":[45,146],"image":[46,114,202],"models,":[47,88],"under":[48],"either":[49],"white-box":[51,81],"setting,":[52],"where":[53,66],"an":[54,67,185],"adversary":[55,68],"full":[57],"access":[58],"model":[60,74],"parameters,":[61],"or":[62,77],"black-box":[64,89,103,201,242],"setting":[65],"only":[70,184],"query":[71],"target":[73,133],"probabilities":[76],"labels.":[78],"Whilst":[79],"several":[80],"attacks":[82,91,165],"been":[84],"proposed":[85],"video":[87,90,104,153,171,238],"still":[93],"unexplored.":[94],"To":[95],"close":[96],"this":[97],"gap,":[98],"we":[99,155],"propose":[100],"first":[102],"attack":[105],"framework,":[106],"called":[107],"V-BAD.":[108],"V-BAD":[109,135,158,225],"utilizestentative":[110],"perturbations":[111],"transferred":[112],"from":[113],"models":[115,240],"andpartition-based":[116],"rectifications":[117],"found":[118],"by":[119],"NES":[121],"obtain":[123],"good":[124],"gradient":[126,145],"estimates":[127],"with":[128],"fewer":[129],"queries":[130,198],"model.":[134],"is":[136,205,226],"equivalent":[137],"estimating":[139],"projection":[141],"selected":[148],"subspace.":[149],"Using":[150],"three":[151],"benchmark":[152],"datasets,":[154],"demonstrate":[156],"craft":[160],"both":[161],"untargeted":[162],"targeted":[164,176],"two":[168,213],"state-of-the-art":[169,200],"deep":[170],"recognition":[172,239],"models.":[173],"For":[174],"attack,":[177],"it":[178],"achieves":[179],"$>$93%":[180],"success":[181],"rate":[182],"using":[183],"average":[186],"$3.4":[188],"\\sim":[189],"8.4":[190],"\\times":[191],"10^4$":[192],"queries,":[193],"similar":[195],"number":[196],"attacks.":[203,244],"This":[204],"despite":[206],"fact":[208],"videos":[210],"often":[211],"orders":[214],"magnitude":[216],"higher":[217],"dimensionality":[218],"than":[219],"static":[220],"images.":[221],"We":[222],"believe":[223],"promising":[228],"new":[229],"tool":[230],"evaluate":[232],"improve":[234],"robustness":[236]},"counts_by_year":[{"year":2026,"cited_by_count":2},{"year":2025,"cited_by_count":23},{"year":2024,"cited_by_count":15},{"year":2023,"cited_by_count":24},{"year":2022,"cited_by_count":21},{"year":2021,"cited_by_count":30},{"year":2020,"cited_by_count":30},{"year":2019,"cited_by_count":2}],"updated_date":"2026-04-15T08:11:43.952461","created_date":"2025-10-10T00:00:00"}
