{"id":"https://openalex.org/W7125392896","doi":"https://doi.org/10.48550/arxiv.2601.14300","title":"Gradient Structure Estimation under Label-Only Oracles via Spectral Sensitivity","display_name":"Gradient Structure Estimation under Label-Only Oracles via Spectral Sensitivity","publication_year":2026,"publication_date":"2026-01-17","ids":{"openalex":"https://openalex.org/W7125392896","doi":"https://doi.org/10.48550/arxiv.2601.14300"},"language":null,"primary_location":{"id":"doi:10.48550/arxiv.2601.14300","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2601.14300","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://doi.org/10.48550/arxiv.2601.14300","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5123542714","display_name":"Jun Liu","orcid":null},"institutions":[],"countries":[],"is_corresponding":true,"raw_author_name":"Liu, Jun","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5123549283","display_name":"Leo Yu Zhang","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Zhang, Leo Yu","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5008409933","display_name":"Fengpeng Li","orcid":"https://orcid.org/0000-0001-5080-7425"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Li, Fengpeng","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5121583508","display_name":"Isao Echizen","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Echizen, Isao","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5123603756","display_name":"Jiantao Zhou","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Zhou, Jiantao","raw_affiliation_strings":[],"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5123542714"],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9902999997138977,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9902999997138977,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10036","display_name":"Advanced Neural Network Applications","score":0.002899999963119626,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.000699999975040555,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/initialization","display_name":"Initialization","score":0.7660999894142151},{"id":"https://openalex.org/keywords/heuristic","display_name":"Heuristic","score":0.5871000289916992},{"id":"https://openalex.org/keywords/sign","display_name":"Sign (mathematics)","score":0.5435000061988831},{"id":"https://openalex.org/keywords/range","display_name":"Range (aeronautics)","score":0.4952999949455261},{"id":"https://openalex.org/keywords/perspective","display_name":"Perspective (graphical)","score":0.4702000021934509},{"id":"https://openalex.org/keywords/code","display_name":"Code (set theory)","score":0.4431999921798706},{"id":"https://openalex.org/keywords/sensitivity","display_name":"Sensitivity (control systems)","score":0.4185999929904938},{"id":"https://openalex.org/keywords/gradient-descent","display_name":"Gradient descent","score":0.39250001311302185},{"id":"https://openalex.org/keywords/image","display_name":"Image (mathematics)","score":0.37049999833106995}],"concepts":[{"id":"https://openalex.org/C114466953","wikidata":"https://www.wikidata.org/wiki/Q6034165","display_name":"Initialization","level":2,"score":0.7660999894142151},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6055999994277954},{"id":"https://openalex.org/C173801870","wikidata":"https://www.wikidata.org/wiki/Q201413","display_name":"Heuristic","level":2,"score":0.5871000289916992},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.5550000071525574},{"id":"https://openalex.org/C139676723","wikidata":"https://www.wikidata.org/wiki/Q1193832","display_name":"Sign (mathematics)","level":2,"score":0.5435000061988831},{"id":"https://openalex.org/C204323151","wikidata":"https://www.wikidata.org/wiki/Q905424","display_name":"Range (aeronautics)","level":2,"score":0.4952999949455261},{"id":"https://openalex.org/C12713177","wikidata":"https://www.wikidata.org/wiki/Q1900281","display_name":"Perspective (graphical)","level":2,"score":0.4702000021934509},{"id":"https://openalex.org/C2776760102","wikidata":"https://www.wikidata.org/wiki/Q5139990","display_name":"Code (set theory)","level":3,"score":0.4431999921798706},{"id":"https://openalex.org/C21200559","wikidata":"https://www.wikidata.org/wiki/Q7451068","display_name":"Sensitivity (control systems)","level":2,"score":0.4185999929904938},{"id":"https://openalex.org/C153258448","wikidata":"https://www.wikidata.org/wiki/Q1199743","display_name":"Gradient descent","level":3,"score":0.39250001311302185},{"id":"https://openalex.org/C115961682","wikidata":"https://www.wikidata.org/wiki/Q860623","display_name":"Image (mathematics)","level":2,"score":0.37049999833106995},{"id":"https://openalex.org/C28719098","wikidata":"https://www.wikidata.org/wiki/Q44946","display_name":"Point (geometry)","level":2,"score":0.34929999709129333},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.3481999933719635},{"id":"https://openalex.org/C99498987","wikidata":"https://www.wikidata.org/wiki/Q2210247","display_name":"Noise (video)","level":3,"score":0.3346000015735626},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.3319999873638153},{"id":"https://openalex.org/C2776502983","wikidata":"https://www.wikidata.org/wiki/Q690182","display_name":"Contrast (vision)","level":2,"score":0.3287999927997589},{"id":"https://openalex.org/C103278499","wikidata":"https://www.wikidata.org/wiki/Q254465","display_name":"Similarity (geometry)","level":3,"score":0.32839998602867126},{"id":"https://openalex.org/C2780762811","wikidata":"https://www.wikidata.org/wiki/Q1784941","display_name":"Cosine similarity","level":3,"score":0.32589998841285706},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.32269999384880066},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.3093000054359436},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.3077999949455261},{"id":"https://openalex.org/C108010975","wikidata":"https://www.wikidata.org/wiki/Q500094","display_name":"Pruning","level":2,"score":0.30090001225471497},{"id":"https://openalex.org/C115680565","wikidata":"https://www.wikidata.org/wiki/Q5977448","display_name":"Gradient method","level":2,"score":0.2953999936580658},{"id":"https://openalex.org/C2164484","wikidata":"https://www.wikidata.org/wiki/Q5170150","display_name":"Core (optical fiber)","level":2,"score":0.2930000126361847},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.2721000015735626},{"id":"https://openalex.org/C99138194","wikidata":"https://www.wikidata.org/wiki/Q183427","display_name":"Hash function","level":2,"score":0.26980000734329224},{"id":"https://openalex.org/C77618280","wikidata":"https://www.wikidata.org/wiki/Q1155772","display_name":"Scheme (mathematics)","level":2,"score":0.2574000060558319}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.48550/arxiv.2601.14300","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2601.14300","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"doi:10.48550/arxiv.2601.14300","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2601.14300","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Hard-label":[0],"black-box":[1],"settings,":[2],"where":[3],"only":[4],"top-1":[5],"predicted":[6],"labels":[7],"are":[8],"observable,":[9],"pose":[10],"a":[11,46,52,99,105,110,224,230],"fundamentally":[12],"constrained":[13],"yet":[14],"practically":[15],"important":[16],"feedback":[17],"model":[18,21],"for":[19],"understanding":[20],"behavior.":[22],"A":[23],"central":[24],"challenge":[25],"in":[26,190,199,229],"this":[27,42,94],"regime":[28],"is":[29],"whether":[30],"meaningful":[31],"gradient":[32,85,134],"information":[33],"can":[34,60],"be":[35,61,237],"recovered":[36],"from":[37,78],"such":[38],"discrete":[39],"responses.":[40],"In":[41],"work,":[43],"we":[44,97],"develop":[45],"unified":[47],"theoretical":[48,117],"perspective":[49],"showing":[50],"that":[51,103,182],"wide":[53],"range":[54],"of":[55,68,84],"existing":[56,151],"sign-flipping":[57],"hard-label":[58,76,188],"attacks":[59,77,189],"interpreted":[62],"as":[63],"implicitly":[64],"approximating":[65],"the":[66,69,132,141],"sign":[67,86,135],"true":[70,133],"loss":[71],"gradient.":[72],"This":[73],"observation":[74],"reframes":[75],"heuristic":[79],"search":[80,153],"procedures":[81],"into":[82],"instances":[83],"recovery":[87],"under":[88,121],"extremely":[89],"limited":[90],"feedback.":[91],"Motivated":[92],"by":[93],"first-principles":[95],"understanding,":[96],"propose":[98],"new":[100],"attack":[101,192],"framework":[102,159],"combines":[104],"zero-query":[106],"frequency-domain":[107],"initialization":[108,125],"with":[109],"Pattern-Driven":[111],"Optimization":[112],"(PDO)":[113],"strategy.":[114],"We":[115,155],"establish":[116],"guarantees":[118],"demonstrating":[119],"that,":[120],"mild":[122],"assumptions,":[123],"our":[124,158,183,205],"achieves":[126],"higher":[127],"expected":[128],"cosine":[129],"similarity":[130],"to":[131,137,209],"compared":[136],"random":[138],"baselines,":[139],"while":[140],"proposed":[142],"PDO":[143],"procedure":[144],"attains":[145],"substantially":[146],"lower":[147],"query":[148,196],"complexity":[149],"than":[150],"structured":[152],"approaches.":[154],"empirically":[156],"validate":[157],"through":[160],"extensive":[161],"experiments":[162],"on":[163],"CIFAR-10,":[164],"ImageNet,":[165],"and":[166,170,176,195,214],"ObjectNet,":[167],"covering":[168],"standard":[169],"adversarially":[171],"trained":[172],"models,":[173],"commercial":[174],"APIs,":[175],"CLIP-based":[177],"models.":[178],"The":[179],"results":[180],"show":[181],"method":[184],"consistently":[185],"surpasses":[186],"SOTA":[187,225],"both":[191],"success":[193],"rate":[194],"efficiency,":[197],"particularly":[198],"low-query":[200],"regimes.":[201],"Beyond":[202],"image":[203],"classification,":[204],"approach":[206],"generalizes":[207],"effectively":[208],"corrupted":[210],"data,":[211],"biomedical":[212],"datasets,":[213],"dense":[215],"prediction":[216],"tasks.":[217],"Notably,":[218],"it":[219],"also":[220],"successfully":[221],"circumvents":[222],"Blacklight,":[223],"stateful":[226],"defense,":[227],"resulting":[228],"$0\\%$":[231],"detection":[232],"rate.":[233],"Our":[234],"code":[235],"will":[236],"released":[238],"publicly":[239],"soon":[240],"at":[241],"https://github.com/csjunjun/DPAttack.git.":[242]},"counts_by_year":[],"updated_date":"2026-01-23T23:24:52.574035","created_date":"2026-01-23T00:00:00"}
