{"id":"https://openalex.org/W4293785471","doi":"https://doi.org/10.1145/3511808.3557276","title":"Cross-domain Cross-architecture Black-box Attacks on Fine-tuned Models with Transferred Evolutionary Strategies","display_name":"Cross-domain Cross-architecture Black-box Attacks on Fine-tuned Models with Transferred Evolutionary Strategies","publication_year":2022,"publication_date":"2022-10-16","ids":{"openalex":"https://openalex.org/W4293785471","doi":"https://doi.org/10.1145/3511808.3557276"},"language":"en","primary_location":{"id":"doi:10.1145/3511808.3557276","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3511808.3557276","pdf_url":null,"source":{"id":"https://openalex.org/S4363608762","display_name":"Proceedings of the 31st ACM International Conference on Information &amp; Knowledge Management","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 31st ACM International Conference on Information &amp; Knowledge Management","raw_type":"proceedings-article"},"type":"article","indexed_in":["arxiv","crossref"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://arxiv.org/pdf/2208.13182","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5100648511","display_name":"Yinghua Zhang","orcid":"https://orcid.org/0000-0003-0324-4812"},"institutions":[{"id":"https://openalex.org/I200769079","display_name":"Hong Kong University of Science and Technology","ror":"https://ror.org/00q4vv597","country_code":"HK","type":"education","lineage":["https://openalex.org/I200769079"]}],"countries":["HK"],"is_corresponding":true,"raw_author_name":"Yinghua Zhang","raw_affiliation_strings":["Hong Kong University of Science and Technology, Hong Kong, Hong Kong"],"affiliations":[{"raw_affiliation_string":"Hong Kong University of Science and Technology, Hong Kong, Hong Kong","institution_ids":["https://openalex.org/I200769079"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5020880385","display_name":"Yangqiu Song","orcid":"https://orcid.org/0000-0002-7818-6090"},"institutions":[{"id":"https://openalex.org/I200769079","display_name":"Hong Kong University of Science and Technology","ror":"https://ror.org/00q4vv597","country_code":"HK","type":"education","lineage":["https://openalex.org/I200769079"]}],"countries":["HK"],"is_corresponding":false,"raw_author_name":"Yangqiu Song","raw_affiliation_strings":["Hong Kong University of Science and Technology, Hong Kong, Hong Kong"],"affiliations":[{"raw_affiliation_string":"Hong Kong University of Science and Technology, Hong Kong, Hong Kong","institution_ids":["https://openalex.org/I200769079"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5102906188","display_name":"Kun Bai","orcid":"https://orcid.org/0000-0002-3773-5364"},"institutions":[{"id":"https://openalex.org/I3132238960","display_name":"Institute of Electrical and Electronics Engineers","ror":"https://ror.org/01n002310","country_code":"US","type":"education","lineage":["https://openalex.org/I3132238960"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Kun Bai","raw_affiliation_strings":["IEEE Senior Member, New York, NY, USA"],"affiliations":[{"raw_affiliation_string":"IEEE Senior Member, New York, NY, USA","institution_ids":["https://openalex.org/I3132238960"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5108037735","display_name":"Qiang Yang","orcid":null},"institutions":[{"id":"https://openalex.org/I200769079","display_name":"Hong Kong University of Science and Technology","ror":"https://ror.org/00q4vv597","country_code":"HK","type":"education","lineage":["https://openalex.org/I200769079"]},{"id":"https://openalex.org/I889458895","display_name":"University of Hong Kong","ror":"https://ror.org/02zhqgq86","country_code":"HK","type":"education","lineage":["https://openalex.org/I889458895"]}],"countries":["HK"],"is_corresponding":false,"raw_author_name":"Qiang Yang","raw_affiliation_strings":["Hong Kong University of Science and Technology, WeBank, Hong Kong, Hong Kong"],"affiliations":[{"raw_affiliation_string":"Hong Kong University of Science and Technology, WeBank, Hong Kong, Hong Kong","institution_ids":["https://openalex.org/I200769079","https://openalex.org/I889458895"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5100648511"],"corresponding_institution_ids":["https://openalex.org/I200769079"],"apc_list":null,"apc_paid":null,"fwci":0.1047,"has_fulltext":false,"cited_by_count":1,"citation_normalized_percentile":{"value":0.29013622,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":90,"max":94},"biblio":{"volume":null,"issue":null,"first_page":"2661","last_page":"2670"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9495000243186951,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11242","display_name":"Nuclear Materials and Properties","score":0.9217000007629395,"subfield":{"id":"https://openalex.org/subfields/2505","display_name":"Materials Chemistry"},"field":{"id":"https://openalex.org/fields/25","display_name":"Materials Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8092761039733887},{"id":"https://openalex.org/keywords/generator","display_name":"Generator (circuit theory)","score":0.7251794338226318},{"id":"https://openalex.org/keywords/domain","display_name":"Domain (mathematical analysis)","score":0.6872369647026062},{"id":"https://openalex.org/keywords/encoder","display_name":"Encoder","score":0.6627792119979858},{"id":"https://openalex.org/keywords/architecture","display_name":"Architecture","score":0.6422589421272278},{"id":"https://openalex.org/keywords/black-box","display_name":"Black box","score":0.5977312326431274},{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.5974138379096985},{"id":"https://openalex.org/keywords/fine-tuning","display_name":"Fine-tuning","score":0.43619421124458313},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.3133102059364319},{"id":"https://openalex.org/keywords/power","display_name":"Power (physics)","score":0.10886168479919434},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.07324182987213135},{"id":"https://openalex.org/keywords/mathematics","display_name":"Mathematics","score":0.0626184344291687}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8092761039733887},{"id":"https://openalex.org/C2780992000","wikidata":"https://www.wikidata.org/wiki/Q17016113","display_name":"Generator (circuit theory)","level":3,"score":0.7251794338226318},{"id":"https://openalex.org/C36503486","wikidata":"https://www.wikidata.org/wiki/Q11235244","display_name":"Domain (mathematical analysis)","level":2,"score":0.6872369647026062},{"id":"https://openalex.org/C118505674","wikidata":"https://www.wikidata.org/wiki/Q42586063","display_name":"Encoder","level":2,"score":0.6627792119979858},{"id":"https://openalex.org/C123657996","wikidata":"https://www.wikidata.org/wiki/Q12271","display_name":"Architecture","level":2,"score":0.6422589421272278},{"id":"https://openalex.org/C94966114","wikidata":"https://www.wikidata.org/wiki/Q29256","display_name":"Black box","level":2,"score":0.5977312326431274},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.5974138379096985},{"id":"https://openalex.org/C157524613","wikidata":"https://www.wikidata.org/wiki/Q2828883","display_name":"Fine-tuning","level":2,"score":0.43619421124458313},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.3133102059364319},{"id":"https://openalex.org/C163258240","wikidata":"https://www.wikidata.org/wiki/Q25342","display_name":"Power (physics)","level":2,"score":0.10886168479919434},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.07324182987213135},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.0626184344291687},{"id":"https://openalex.org/C142362112","wikidata":"https://www.wikidata.org/wiki/Q735","display_name":"Art","level":0,"score":0.0},{"id":"https://openalex.org/C121332964","wikidata":"https://www.wikidata.org/wiki/Q413","display_name":"Physics","level":0,"score":0.0},{"id":"https://openalex.org/C153349607","wikidata":"https://www.wikidata.org/wiki/Q36649","display_name":"Visual arts","level":1,"score":0.0},{"id":"https://openalex.org/C134306372","wikidata":"https://www.wikidata.org/wiki/Q7754","display_name":"Mathematical analysis","level":1,"score":0.0},{"id":"https://openalex.org/C62520636","wikidata":"https://www.wikidata.org/wiki/Q944","display_name":"Quantum mechanics","level":1,"score":0.0}],"mesh":[],"locations_count":3,"locations":[{"id":"doi:10.1145/3511808.3557276","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3511808.3557276","pdf_url":null,"source":{"id":"https://openalex.org/S4363608762","display_name":"Proceedings of the 31st ACM International Conference on Information &amp; Knowledge Management","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 31st ACM International Conference on Information &amp; Knowledge Management","raw_type":"proceedings-article"},{"id":"pmh:oai:arXiv.org:2208.13182","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2208.13182","pdf_url":"https://arxiv.org/pdf/2208.13182","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},{"id":"pmh:oai:repository.hkust.edu.hk:1783.1-123748","is_oa":false,"landing_page_url":"https://repository.hkust.edu.hk/ir/Record/1783.1-123748","pdf_url":null,"source":{"id":"https://openalex.org/S4306401796","display_name":"Rare & Special e-Zone (The Hong Kong University of Science and Technology)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I200769079","host_organization_name":"Hong Kong University of Science and Technology","host_organization_lineage":["https://openalex.org/I200769079"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":"Conference paper"}],"best_oa_location":{"id":"pmh:oai:arXiv.org:2208.13182","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2208.13182","pdf_url":"https://arxiv.org/pdf/2208.13182","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/11","display_name":"Sustainable cities and communities","score":0.550000011920929}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":41,"referenced_works":["https://openalex.org/W1673923490","https://openalex.org/W1686810756","https://openalex.org/W1821462560","https://openalex.org/W1945616565","https://openalex.org/W2117539524","https://openalex.org/W2180612164","https://openalex.org/W2183341477","https://openalex.org/W2194775991","https://openalex.org/W2243397390","https://openalex.org/W2570685808","https://openalex.org/W2603766943","https://openalex.org/W2627183927","https://openalex.org/W2781800156","https://openalex.org/W2888940765","https://openalex.org/W2895097814","https://openalex.org/W2913266441","https://openalex.org/W2947821610","https://openalex.org/W2951226532","https://openalex.org/W2952104986","https://openalex.org/W2963062382","https://openalex.org/W2963070423","https://openalex.org/W2963178695","https://openalex.org/W2963361074","https://openalex.org/W2963542245","https://openalex.org/W2963744840","https://openalex.org/W2963857521","https://openalex.org/W2964205597","https://openalex.org/W2964346747","https://openalex.org/W2970257215","https://openalex.org/W2970971581","https://openalex.org/W2982767129","https://openalex.org/W3080297477","https://openalex.org/W3080797848","https://openalex.org/W3106412272","https://openalex.org/W3215624426","https://openalex.org/W4288103143","https://openalex.org/W4293846201","https://openalex.org/W4295312788","https://openalex.org/W4300473403","https://openalex.org/W4301320022","https://openalex.org/W4324128313"],"related_works":["https://openalex.org/W2502115930","https://openalex.org/W2482350142","https://openalex.org/W4246396837","https://openalex.org/W3126451824","https://openalex.org/W1561927205","https://openalex.org/W3191453585","https://openalex.org/W4297672492","https://openalex.org/W3009622996","https://openalex.org/W3037859390","https://openalex.org/W4391988129"],"abstract_inverted_index":{"Fine-tuning":[0],"can":[1,141],"be":[2],"vulnerable":[3],"to":[4,70,90],"adversarial":[5,74,92,108],"attacks.":[6],"Existing":[7],"works":[8],"about":[9],"black-box":[10],"attacks":[11],"on":[12,128],"fine-tuned":[13,48,63,147],"models":[14,64],"(BAFT)":[15],"are":[16],"limited":[17],"by":[18,103],"strong":[19],"assumptions.":[20],"To":[21,60],"fill":[22],"the":[23,41,52,77,98,104,107,115,118,123,137,146],"gap,":[24],"we":[25,68,95],"propose":[26,69],"two":[27],"novel":[28],"BAFT":[29],"settings,":[30,67],"cross-domain":[31,33],"and":[32,50,58,85,131,143],"cross-architecture":[34],"BAFT,":[35],"which":[36,80],"only":[37],"assume":[38],"that":[39,136],"(1)":[40],"target":[42],"model":[43],"for":[44],"attacking":[45],"is":[46,56,112],"a":[47,87],"model,":[49,79],"(2)":[51],"source":[53,78,124],"domain":[54],"data":[55],"known":[57],"accessible.":[59],"successfully":[61],"attack":[62,139,145],"under":[65,114],"both":[66],"first":[71],"train":[72],"an":[73,82,91],"generator":[75],"against":[76],"adopts":[81],"encoder-decoder":[83],"architecture":[84],"maps":[86],"clean":[88],"input":[89],"example.":[93],"Then":[94],"search":[96,111],"in":[97],"low-dimensional":[99],"latent":[100],"space":[101],"produced":[102],"encoder":[105],"of":[106,117],"generator.":[109],"The":[110],"conducted":[113],"guidance":[116],"surrogate":[119],"gradient":[120],"obtained":[121],"from":[122],"model.":[125],"Experimental":[126],"results":[127],"different":[129,132],"domains":[130],"network":[133],"architectures":[134],"demonstrate":[135],"proposed":[138],"method":[140],"effectively":[142],"efficiently":[144],"models.":[148]},"counts_by_year":[{"year":2024,"cited_by_count":1}],"updated_date":"2026-03-20T23:20:44.827607","created_date":"2025-10-10T00:00:00"}
