{"id":"https://openalex.org/W4403577849","doi":"https://doi.org/10.1145/3627673.3679639","title":"SGFL-Attack: A Similarity-Guidance Strategy for Hard-Label Textual Adversarial Attack Based on Feedback Learning","display_name":"SGFL-Attack: A Similarity-Guidance Strategy for Hard-Label Textual Adversarial Attack Based on Feedback Learning","publication_year":2024,"publication_date":"2024-10-20","ids":{"openalex":"https://openalex.org/W4403577849","doi":"https://doi.org/10.1145/3627673.3679639"},"language":"en","primary_location":{"id":"doi:10.1145/3627673.3679639","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3627673.3679639","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 33rd ACM International Conference on Information and Knowledge Management","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5114337382","display_name":"Panjia Qiu","orcid":"https://orcid.org/0009-0008-4788-8998"},"institutions":[{"id":"https://openalex.org/I66867065","display_name":"East China Normal University","ror":"https://ror.org/02n96ep67","country_code":"CN","type":"education","lineage":["https://openalex.org/I66867065"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Panjia Qiu","raw_affiliation_strings":["East China Normal University, Shanghai, China"],"raw_orcid":"https://orcid.org/0009-0008-4788-8998","affiliations":[{"raw_affiliation_string":"East China Normal University, Shanghai, China","institution_ids":["https://openalex.org/I66867065"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5069373475","display_name":"Guanghao Zhou","orcid":"https://orcid.org/0009-0006-4549-4800"},"institutions":[{"id":"https://openalex.org/I66867065","display_name":"East China Normal University","ror":"https://ror.org/02n96ep67","country_code":"CN","type":"education","lineage":["https://openalex.org/I66867065"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Guanghao Zhou","raw_affiliation_strings":["East China Normal University, Shanghai, China"],"raw_orcid":"https://orcid.org/0009-0006-4549-4800","affiliations":[{"raw_affiliation_string":"East China Normal University, Shanghai, China","institution_ids":["https://openalex.org/I66867065"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5064674050","display_name":"Mingyuan Fan","orcid":"https://orcid.org/0000-0001-9550-9237"},"institutions":[{"id":"https://openalex.org/I66867065","display_name":"East China Normal University","ror":"https://ror.org/02n96ep67","country_code":"CN","type":"education","lineage":["https://openalex.org/I66867065"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Mingyuan Fan","raw_affiliation_strings":["East China Normal University, ShangHai, China"],"raw_orcid":"https://orcid.org/0000-0001-9550-9237","affiliations":[{"raw_affiliation_string":"East China Normal University, ShangHai, China","institution_ids":["https://openalex.org/I66867065"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5114734448","display_name":"Cen Chen","orcid":"https://orcid.org/0000-0003-0325-1705"},"institutions":[{"id":"https://openalex.org/I66867065","display_name":"East China Normal University","ror":"https://ror.org/02n96ep67","country_code":"CN","type":"education","lineage":["https://openalex.org/I66867065"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Cen Chen","raw_affiliation_strings":["East China Normal University, ShangHai, China"],"raw_orcid":"https://orcid.org/0000-0003-0325-1705","affiliations":[{"raw_affiliation_string":"East China Normal University, ShangHai, China","institution_ids":["https://openalex.org/I66867065"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5046576694","display_name":"Yaliang Li","orcid":"https://orcid.org/0000-0002-4204-6096"},"institutions":[{"id":"https://openalex.org/I45928872","display_name":"Alibaba Group (China)","ror":"https://ror.org/00k642b80","country_code":"CN","type":"company","lineage":["https://openalex.org/I45928872"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yaliang Li","raw_affiliation_strings":["Alibaba Group, Hangzhou, China"],"raw_orcid":"https://orcid.org/0000-0002-4204-6096","affiliations":[{"raw_affiliation_string":"Alibaba Group, Hangzhou, China","institution_ids":["https://openalex.org/I45928872"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5016155107","display_name":"Wenmeng Zhou","orcid":"https://orcid.org/0000-0001-9967-5515"},"institutions":[{"id":"https://openalex.org/I45928872","display_name":"Alibaba Group (China)","ror":"https://ror.org/00k642b80","country_code":"CN","type":"company","lineage":["https://openalex.org/I45928872"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Wenming Zhou","raw_affiliation_strings":["Alibaba Group, Hangzhou, China"],"raw_orcid":"https://orcid.org/0000-0001-9967-5515","affiliations":[{"raw_affiliation_string":"Alibaba Group, Hangzhou, China","institution_ids":["https://openalex.org/I45928872"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":6,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.3055,"has_fulltext":false,"cited_by_count":1,"citation_normalized_percentile":{"value":0.65786161,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":95,"max":98},"biblio":{"volume":null,"issue":null,"first_page":"1920","last_page":"1929"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9994999766349792,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9994999766349792,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9585000276565552,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.8697307109832764},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7686504125595093},{"id":"https://openalex.org/keywords/similarity","display_name":"Similarity (geometry)","score":0.7158111929893494},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.5357180237770081},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.3816070556640625}],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.8697307109832764},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7686504125595093},{"id":"https://openalex.org/C103278499","wikidata":"https://www.wikidata.org/wiki/Q254465","display_name":"Similarity (geometry)","level":3,"score":0.7158111929893494},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5357180237770081},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.3816070556640625},{"id":"https://openalex.org/C115961682","wikidata":"https://www.wikidata.org/wiki/Q860623","display_name":"Image (mathematics)","level":2,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3627673.3679639","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3627673.3679639","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 33rd ACM International Conference on Information and Knowledge Management","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":9,"referenced_works":["https://openalex.org/W2194775991","https://openalex.org/W2949128310","https://openalex.org/W2962818281","https://openalex.org/W2996851481","https://openalex.org/W3015625436","https://openalex.org/W3117433489","https://openalex.org/W4283811884","https://openalex.org/W4290944423","https://openalex.org/W4385562585"],"related_works":["https://openalex.org/W2961085424","https://openalex.org/W4306674287","https://openalex.org/W3046775127","https://openalex.org/W3107602296","https://openalex.org/W4394896187","https://openalex.org/W3170094116","https://openalex.org/W4386462264","https://openalex.org/W4364306694","https://openalex.org/W4312192474","https://openalex.org/W4283697347"],"abstract_inverted_index":{"Hard-label":[0],"black-box":[1],"textual":[2,136],"adversarial":[3,137],"attack":[4],"presents":[5],"a":[6,122,127,164],"challenging":[7],"task":[8,25],"where":[9],"only":[10],"the":[11,14,24,31,41,57,144,153,188,195,210,223,235],"predictions":[12],"of":[13,26,37,89,155],"victim":[15],"model":[16],"are":[17,105],"available.":[18],"Moreover,":[19,207],"several":[20,70],"constraints":[21],"further":[22],"complicate":[23],"launching":[27],"such":[28],"attacks,":[29],"including":[30],"inherent":[32],"discrete":[33,94],"and":[34,40,157,162,243],"non-differentiable":[35],"nature":[36],"text":[38,95,160],"data":[39],"need":[42],"to":[43,50,62,99,107,151,168,208,218],"introduce":[44,120],"subtle":[45],"perturbations":[46],"that":[47,125,234],"remain":[48],"imperceptible":[49],"humans":[51],"while":[52,203],"preserving":[53],"semantic":[54],"similarity.":[55],"Despite":[56],"considerable":[58],"research":[59],"efforts":[60],"dedicated":[61],"this":[63,117],"problem,":[64],"existing":[65],"methods":[66],"still":[67],"suffer":[68],"from":[69,194],"limitations.":[71],"For":[72],"example,":[73],"algorithms":[74],"based":[75,130,173,190],"on":[76,131,174,191,228],"complex":[77],"heuristic":[78],"searches":[79],"necessitate":[80],"extensive":[81],"querying,":[82],"rendering":[83],"them":[84],"computationally":[85],"expensive.":[86],"The":[87],"introduction":[88],"continuous":[90],"gradient":[91],"strategies":[92,104],"into":[93,109],"spaces":[96],"often":[97],"leads":[98],"estimation":[100],"errors.":[101],"Meanwhile,":[102],"geometry-based":[103],"prone":[106],"falling":[108],"local":[110,215],"optima.":[111],"To":[112],"address":[113],"these":[114],"limitations,":[115],"in":[116,159,176],"paper,":[118],"we":[119,213],"SGFL-Attack,":[121],"novel":[123],"approach":[124],"leverages":[126],"<u>S</u>imilarity-<u>G</u>uidance":[128],"strategy":[129],"<u>F</u>eedback":[132],"<u>L</u>earning":[133],"for":[134],"hard-label":[135],"attack,":[138],"with":[139],"limited":[140],"query":[141,211],"budget.":[142],"Specifically,":[143],"proposed":[145,236],"SGFL-Attack":[146,186,237],"utilizes":[147],"word":[148],"embedding":[149],"vectors":[150],"assess":[152],"importance":[154],"words":[156],"positions":[158],"sequences,":[161],"employs":[163],"feedback":[165,196],"learning":[166,197],"mechanism":[167],"determine":[169],"reward":[170],"or":[171],"punishment":[172],"changes":[175],"predicted":[177],"labels":[178],"caused":[179],"by":[180],"replacing":[181],"words.":[182],"In":[183],"each":[184],"iteration,":[185],"guides":[187],"search":[189,224],"knowledge":[192],"acquired":[193],"mechanism,":[198],"generating":[199],"more":[200],"similar":[201],"samples":[202],"maintaining":[204],"low":[205],"perturbations.":[206],"reduce":[209],"budget,":[212],"incorporate":[214],"hash":[216],"mapping":[217],"avoid":[219],"redundant":[220],"queries":[221],"during":[222],"process.":[225],"Extensive":[226],"experiments":[227],"seven":[229],"widely":[230],"used":[231],"datasets":[232],"show":[233],"method":[238],"significantly":[239],"outperforms":[240],"state-of-the-art":[241],"baselines":[242],"defenses":[244],"over":[245],"multiple":[246],"language":[247],"models.":[248]},"counts_by_year":[{"year":2026,"cited_by_count":1}],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-10T00:00:00"}
