Pith. sign in

REVIEW 3 cited by

Simple Black-box Adversarial Attacks

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1905.07121 v2 pith:MAPKPZ6B submitted 2019-05-17 cs.LG cs.CRstat.ML

classification cs.LGcs.CRstat.ML
keywords attacksblack-boxadversarialalgorithmsimpleefficiencyimagesmethod
verification ladder T0 review T1 audit T2 compute T3 formal

Signed reviews

No signed human review yet.

0 comments
read the original abstract

We propose an intriguingly simple method for the construction of adversarial images in the black-box setting. In constrast to the white-box scenario, constructing black-box adversarial images has the additional constraint on query budget, and efficient attacks remain an open problem to date. With only the mild assumption of continuous-valued confidence scores, our highly query-efficient algorithm utilizes the following simple iterative principle: we randomly sample a vector from a predefined orthonormal basis and either add or subtract it to the target image. Despite its simplicity, the proposed method can be used for both untargeted and targeted attacks -- resulting in previously unprecedented query efficiency in both settings. We demonstrate the efficacy and efficiency of our algorithm on several real world settings including the Google Cloud Vision API. We argue that our proposed algorithm should serve as a strong baseline for future black-box attacks, in particular because it is extremely fast and its implementation requires less than 20 lines of PyTorch code.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 3 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Large-scale Testing Global Optimization Methods with Black-box Adversarial Attacks

    cs.LG 2026-08 conditional novelty 6.0 of 10

    The paper proposes black-box adversarial attacks on image classifiers as a high-dimensional benchmark for global optimization and compares seven metaheuristics under shared query budgets.

  2. LLM-Guided Program Evolution for Targeted Black-Box Attacks on Perceptual Hash Algorithms

    cs.CR 2026-07 conditional novelty 6.0 of 10

    Evolved attack programs cut a composite success–query–distortion score by 8–41% versus best optimized seeds on pHash, PDQ, PhotoDNA, and NeuralHash under a graded black-box oracle.

  3. Revisiting Adversarial Perception Attacks and Defense Methods on Autonomous Driving Systems

    cs.RO 2025-05 conditional novelty 4.0 of 10

    Adversarial attacks shift OpenPilot distance estimates by tens of meters and cut YOLOv8 stop sign recall sharply, while tested defenses trade off gains against new failure modes.

Pith tools