{"id":"https://openalex.org/W4285602403","doi":"https://doi.org/10.24963/ijcai.2022/464","title":"A Few Seconds Can Change Everything: Fast Decision-based Attacks against DNNs","display_name":"A Few Seconds Can Change Everything: Fast Decision-based Attacks against DNNs","publication_year":2022,"publication_date":"2022-07-01","ids":{"openalex":"https://openalex.org/W4285602403","doi":"https://doi.org/10.24963/ijcai.2022/464"},"language":"en","primary_location":{"id":"doi:10.24963/ijcai.2022/464","is_oa":true,"landing_page_url":"https://doi.org/10.24963/ijcai.2022/464","pdf_url":"https://www.ijcai.org/proceedings/2022/0464.pdf","source":{"id":"https://openalex.org/S4363608755","display_name":"Proceedings of the Thirty-First International Joint Conference on Artificial Intelligence","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the Thirty-First International Joint Conference on Artificial Intelligence","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"bronze","oa_url":"https://www.ijcai.org/proceedings/2022/0464.pdf","any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5043542221","display_name":"Ningping Mou","orcid":null},"institutions":[{"id":"https://openalex.org/I37461747","display_name":"Wuhan University","ror":"https://ror.org/033vjfk17","country_code":"CN","type":"education","lineage":["https://openalex.org/I37461747"]},{"id":"https://openalex.org/I4210154851","display_name":"Hubei University of Education","ror":"https://ror.org/04f41cb79","country_code":"CN","type":"education","lineage":["https://openalex.org/I4210154851"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Ningping Mou","raw_affiliation_strings":["Wuhan University","The Key Laboratory of Aerospace Information Security and Trusted Computing, Ministry of Education, School of Cyber Sci-ence and Engineering, Wuhan University, Wuhan 430072, Hubei, China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Wuhan University","institution_ids":["https://openalex.org/I37461747"]},{"raw_affiliation_string":"The Key Laboratory of Aerospace Information Security and Trusted Computing, Ministry of Education, School of Cyber Sci-ence and Engineering, Wuhan University, Wuhan 430072, Hubei, China","institution_ids":["https://openalex.org/I4210154851"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5065046158","display_name":"Baolin Zheng","orcid":"https://orcid.org/0009-0002-0381-0255"},"institutions":[{"id":"https://openalex.org/I37461747","display_name":"Wuhan University","ror":"https://ror.org/033vjfk17","country_code":"CN","type":"education","lineage":["https://openalex.org/I37461747"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Baolin Zheng","raw_affiliation_strings":["Wuhan university","School of Computer Science, Wuhan University, Wuhan 430072, Hubei, China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Wuhan university","institution_ids":["https://openalex.org/I37461747"]},{"raw_affiliation_string":"School of Computer Science, Wuhan University, Wuhan 430072, Hubei, China","institution_ids":["https://openalex.org/I37461747"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100391116","display_name":"Qian Wang","orcid":"https://orcid.org/0000-0002-8967-8525"},"institutions":[{"id":"https://openalex.org/I37461747","display_name":"Wuhan University","ror":"https://ror.org/033vjfk17","country_code":"CN","type":"education","lineage":["https://openalex.org/I37461747"]},{"id":"https://openalex.org/I4210154851","display_name":"Hubei University of Education","ror":"https://ror.org/04f41cb79","country_code":"CN","type":"education","lineage":["https://openalex.org/I4210154851"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Qian Wang","raw_affiliation_strings":["Wuhan University","The Key Laboratory of Aerospace Information Security and Trusted Computing, Ministry of Education, School of Cyber Sci-ence and Engineering, Wuhan University, Wuhan 430072, Hubei, China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Wuhan University","institution_ids":["https://openalex.org/I37461747"]},{"raw_affiliation_string":"The Key Laboratory of Aerospace Information Security and Trusted Computing, Ministry of Education, School of Cyber Sci-ence and Engineering, Wuhan University, Wuhan 430072, Hubei, China","institution_ids":["https://openalex.org/I4210154851"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101182247","display_name":"Yunjie Ge","orcid":null},"institutions":[{"id":"https://openalex.org/I37461747","display_name":"Wuhan University","ror":"https://ror.org/033vjfk17","country_code":"CN","type":"education","lineage":["https://openalex.org/I37461747"]},{"id":"https://openalex.org/I4210154851","display_name":"Hubei University of Education","ror":"https://ror.org/04f41cb79","country_code":"CN","type":"education","lineage":["https://openalex.org/I4210154851"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yunjie Ge","raw_affiliation_strings":["Wuhan University","The Key Laboratory of Aerospace Information Security and Trusted Computing, Ministry of Education, School of Cyber Sci-ence and Engineering, Wuhan University, Wuhan 430072, Hubei, China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Wuhan University","institution_ids":["https://openalex.org/I37461747"]},{"raw_affiliation_string":"The Key Laboratory of Aerospace Information Security and Trusted Computing, Ministry of Education, School of Cyber Sci-ence and Engineering, Wuhan University, Wuhan 430072, Hubei, China","institution_ids":["https://openalex.org/I4210154851"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5032766697","display_name":"Binqing Guo","orcid":null},"institutions":[{"id":"https://openalex.org/I37461747","display_name":"Wuhan University","ror":"https://ror.org/033vjfk17","country_code":"CN","type":"education","lineage":["https://openalex.org/I37461747"]},{"id":"https://openalex.org/I4210154851","display_name":"Hubei University of Education","ror":"https://ror.org/04f41cb79","country_code":"CN","type":"education","lineage":["https://openalex.org/I4210154851"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Binqing Guo","raw_affiliation_strings":["Wuhan University","The Key Laboratory of Aerospace Information Security and Trusted Computing, Ministry of Education, School of Cyber Sci-ence and Engineering, Wuhan University, Wuhan 430072, Hubei, China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Wuhan University","institution_ids":["https://openalex.org/I37461747"]},{"raw_affiliation_string":"The Key Laboratory of Aerospace Information Security and Trusted Computing, Ministry of Education, School of Cyber Sci-ence and Engineering, Wuhan University, Wuhan 430072, Hubei, China","institution_ids":["https://openalex.org/I4210154851"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.2076,"has_fulltext":false,"cited_by_count":2,"citation_normalized_percentile":{"value":0.39713756,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":94,"max":96},"biblio":{"volume":null,"issue":null,"first_page":"3342","last_page":"3350"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9625999927520752,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10036","display_name":"Advanced Neural Network Applications","score":0.9578999876976013,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.8626643419265747},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8254666328430176},{"id":"https://openalex.org/keywords/black-box","display_name":"Black box","score":0.5985383987426758},{"id":"https://openalex.org/keywords/domain","display_name":"Domain (mathematical analysis)","score":0.49911975860595703},{"id":"https://openalex.org/keywords/noise","display_name":"Noise (video)","score":0.4868749678134918},{"id":"https://openalex.org/keywords/bridge","display_name":"Bridge (graph theory)","score":0.4597063660621643},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.4273521602153778},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.38639575242996216},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.34594595432281494}],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.8626643419265747},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8254666328430176},{"id":"https://openalex.org/C94966114","wikidata":"https://www.wikidata.org/wiki/Q29256","display_name":"Black box","level":2,"score":0.5985383987426758},{"id":"https://openalex.org/C36503486","wikidata":"https://www.wikidata.org/wiki/Q11235244","display_name":"Domain (mathematical analysis)","level":2,"score":0.49911975860595703},{"id":"https://openalex.org/C99498987","wikidata":"https://www.wikidata.org/wiki/Q2210247","display_name":"Noise (video)","level":3,"score":0.4868749678134918},{"id":"https://openalex.org/C100776233","wikidata":"https://www.wikidata.org/wiki/Q2532492","display_name":"Bridge (graph theory)","level":2,"score":0.4597063660621643},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.4273521602153778},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.38639575242996216},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.34594595432281494},{"id":"https://openalex.org/C115961682","wikidata":"https://www.wikidata.org/wiki/Q860623","display_name":"Image (mathematics)","level":2,"score":0.0},{"id":"https://openalex.org/C134306372","wikidata":"https://www.wikidata.org/wiki/Q7754","display_name":"Mathematical analysis","level":1,"score":0.0},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.0},{"id":"https://openalex.org/C126322002","wikidata":"https://www.wikidata.org/wiki/Q11180","display_name":"Internal medicine","level":1,"score":0.0},{"id":"https://openalex.org/C71924100","wikidata":"https://www.wikidata.org/wiki/Q11190","display_name":"Medicine","level":0,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.24963/ijcai.2022/464","is_oa":true,"landing_page_url":"https://doi.org/10.24963/ijcai.2022/464","pdf_url":"https://www.ijcai.org/proceedings/2022/0464.pdf","source":{"id":"https://openalex.org/S4363608755","display_name":"Proceedings of the Thirty-First International Joint Conference on Artificial Intelligence","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the Thirty-First International Joint Conference on Artificial Intelligence","raw_type":"proceedings-article"}],"best_oa_location":{"id":"doi:10.24963/ijcai.2022/464","is_oa":true,"landing_page_url":"https://doi.org/10.24963/ijcai.2022/464","pdf_url":"https://www.ijcai.org/proceedings/2022/0464.pdf","source":{"id":"https://openalex.org/S4363608755","display_name":"Proceedings of the Thirty-First International Joint Conference on Artificial Intelligence","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the Thirty-First International Joint Conference on Artificial Intelligence","raw_type":"proceedings-article"},"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G2404993877","display_name":null,"funder_award_id":"U20B2049","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G6034313629","display_name":null,"funder_award_id":"U21B2018","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"}],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"}],"has_content":{"grobid_xml":true,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W4285602403.pdf","grobid_xml":"https://content.openalex.org/works/W4285602403.grobid-xml"},"referenced_works_count":24,"referenced_works":["https://openalex.org/W1686810756","https://openalex.org/W1945616565","https://openalex.org/W2108598243","https://openalex.org/W2118858186","https://openalex.org/W2194775991","https://openalex.org/W2533598788","https://openalex.org/W2607219512","https://openalex.org/W2619479788","https://openalex.org/W2895097814","https://openalex.org/W2950782995","https://openalex.org/W2962933288","https://openalex.org/W2963070423","https://openalex.org/W2964346747","https://openalex.org/W2971180473","https://openalex.org/W3015625436","https://openalex.org/W3021997304","https://openalex.org/W3034175346","https://openalex.org/W3034619610","https://openalex.org/W3037843220","https://openalex.org/W3106412272","https://openalex.org/W3170514715","https://openalex.org/W3193940683","https://openalex.org/W3202281277","https://openalex.org/W4293846201"],"related_works":["https://openalex.org/W2502115930","https://openalex.org/W2482350142","https://openalex.org/W4246396837","https://openalex.org/W3126451824","https://openalex.org/W1561927205","https://openalex.org/W3191453585","https://openalex.org/W4297672492","https://openalex.org/W4310988119","https://openalex.org/W3009622996","https://openalex.org/W3037859390"],"abstract_inverted_index":{"Previous":[0],"researches":[1],"have":[2,29],"demonstrated":[3],"deep":[4],"learning":[5],"models'":[6],"vulnerabilities":[7],"to":[8,40,50,150,191],"decision-based":[9,27,59],"adversarial":[10,14,87,99],"attacks,":[11],"which":[12,66,184],"craft":[13],"examples":[15,100],"based":[16],"solely":[17],"on":[18,91,110,161,182],"information":[19,103],"from":[20],"output":[21],"decisions":[22],"(top-1":[23],"labels).":[24],"However,":[25],"existing":[26,86],"attacks":[28,88],"two":[30],"major":[31],"limitations,":[32],"i.e.,":[33],"expensive":[34],"query":[35],"cost":[36],"and":[37,46,57,72,94,126,168,188],"being":[38],"easy":[39],"detect.":[41],"To":[42],"bridge":[43],"the":[44,81,105,118,121,128,135,142],"gap":[45],"enlarge":[47],"real":[48,187],"threats":[49],"commercial":[51,162],"applications,":[52],"we":[53],"propose":[54],"a":[55,69,186],"novel":[56],"efficient":[58],"attack":[60,153,173],"against":[61,154],"black-box":[62,124,156],"models,":[63],"dubbed":[64],"FastDrop,":[65],"only":[67,146],"requires":[68],"few":[70],"queries":[71,131,149,181],"work":[73],"well":[74],"under":[75,134],"strong":[76],"defenses.":[77],"The":[78],"crux":[79],"of":[80,120,130,138,177],"innovation":[82],"is":[83],"that,":[84],"unlike":[85],"that":[89,114],"rely":[90],"gradient":[92],"estimation":[93],"additive":[95],"noise,":[96],"FastDrop":[97,115,145,170],"generates":[98],"by":[101,132,166],"dropping":[102],"in":[104],"frequency":[106],"domain.":[107],"Extensive":[108],"experiments":[109],"three":[111],"datasets":[112],"demonstrate":[113],"can":[116],"escape":[117],"detection":[119],"state-of-the-art":[122],"(SOTA)":[123],"defenses":[125],"reduce":[127],"number":[129],"13~133\u00d7":[133],"same":[136],"level":[137],"perturbations":[139],"compared":[140],"with":[141,179],"SOTA":[143],"attacks.":[144],"needs":[147],"10~20":[148],"conduct":[151],"an":[152,172],"various":[155],"models":[157],"within":[158],"1s.":[159],"Besides,":[160],"vision":[163],"APIs":[164],"provided":[165],"Baidu":[167],"Tencent,":[169],"achieves":[171],"success":[174],"rate":[175],"(ASR)":[176],"100%":[178],"10":[180],"average,":[183],"poses":[185],"severe":[189],"threat":[190],"real-world":[192],"applications.":[193]},"counts_by_year":[{"year":2024,"cited_by_count":2}],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-10T00:00:00"}
