Pith. sign in

REVIEW 2 cited by

Improving Black-box Adversarial Attacks with a Transfer-based Prior

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1906.06919 v3 pith:3JTH344B submitted 2019-06-17 cs.LG cs.CRcs.CVstat.ML

classification cs.LGcs.CRcs.CVstat.ML
keywords adversarialblack-boxgradientmethodspriorquerytransfer-basedattack
verification ladder T0 review T1 audit T2 compute T3 formal

Signed reviews

No signed human review yet.

0 comments
read the original abstract

We consider the black-box adversarial setting, where the adversary has to generate adversarial perturbations without access to the target models to compute gradients. Previous methods tried to approximate the gradient either by using a transfer gradient of a surrogate white-box model, or based on the query feedback. However, these methods often suffer from low attack success rates or poor query efficiency since it is non-trivial to estimate the gradient in a high-dimensional space with limited information. To address these problems, we propose a prior-guided random gradient-free (P-RGF) method to improve black-box adversarial attacks, which takes the advantage of a transfer-based prior and the query information simultaneously. The transfer-based prior given by the gradient of a surrogate model is appropriately integrated into our algorithm by an optimal coefficient derived by a theoretical analysis. Extensive experiments demonstrate that our method requires much fewer queries to attack black-box models with higher success rates compared with the alternative state-of-the-art methods.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. SegPAR: Class-Centric Decision-Based Sparse Attack for Semantic Segmentation

    cs.CV 2026-08 conditional novelty 6.0 of 10

    SegPAR, a class-centric decision-based sparse attack with a discrepancy reward, outperforms black-box sparse baselines in semantic segmentation MIoU reduction and sparsity efficiency.

  2. Hybrid Batch Attacks: Finding Black-box Adversarial Examples with Limited Queries

    cs.CR 2019-08 conditional novelty 6.0 of 10

    Starting black-box optimization attacks from local-model adversarial candidates reduces query cost by up to 81 percent, and seed prioritization lets batch attacks succeed with a few queries.

Pith tools