{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2019:FLIEIUECVESBNADL5WTSQQF6VC","short_pith_number":"pith:FLIEIUEC","schema_version":"1.0","canonical_sha256":"2ad0445082a92416806beda72840bea88a3aa93308b8c79ebdd931ed32ceee18","source":{"kind":"arxiv","id":"1911.07140","version":2},"attestation_state":"computed","paper":{"title":"Black-Box Adversarial Attack with Transferable Model-based Embedding","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["stat.ML"],"primary_cat":"cs.LG","authors_text":"Tong Zhang, Zhichao Huang","submitted_at":"2019-11-17T03:10:49Z","abstract_excerpt":"We present a new method for black-box adversarial attack. Unlike previous methods that combined transfer-based and scored-based methods by using the gradient or initialization of a surrogate white-box model, this new method tries to learn a low-dimensional embedding using a pretrained model, and then performs efficient search within the embedding space to attack an unknown target network. The method produces adversarial perturbations with high level semantic patterns that are easily transferable. We show that this approach can greatly improve the query efficiency of black-box adversarial attac"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"1911.07140","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-11-17T03:10:49Z","cross_cats_sorted":["stat.ML"],"title_canon_sha256":"7d76512651967f02150bb3f9204b1d772ce716bb877b58cc47a54c2396b5dfe4","abstract_canon_sha256":"4c397eb7244a53d219dc231d82ec6d3dadbf6087f7c5a4fd4e3c4685908c143d"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T00:29:41.215914Z","signature_b64":"1DGNhBQ//tpB6eg4YujFLrE+S5IC+bxLvPiDcsibTJJA01W1a4tEX2tjeuAqVzYCDzWjgGivb5OUPdXvN6I1Dw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"2ad0445082a92416806beda72840bea88a3aa93308b8c79ebdd931ed32ceee18","last_reissued_at":"2026-07-05T00:29:41.215441Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T00:29:41.215441Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Black-Box Adversarial Attack with Transferable Model-based Embedding","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["stat.ML"],"primary_cat":"cs.LG","authors_text":"Tong Zhang, Zhichao Huang","submitted_at":"2019-11-17T03:10:49Z","abstract_excerpt":"We present a new method for black-box adversarial attack. Unlike previous methods that combined transfer-based and scored-based methods by using the gradient or initialization of a surrogate white-box model, this new method tries to learn a low-dimensional embedding using a pretrained model, and then performs efficient search within the embedding space to attack an unknown target network. The method produces adversarial perturbations with high level semantic patterns that are easily transferable. We show that this approach can greatly improve the query efficiency of black-box adversarial attac"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1911.07140","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/1911.07140/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"1911.07140","created_at":"2026-07-05T00:29:41.215504+00:00"},{"alias_kind":"arxiv_version","alias_value":"1911.07140v2","created_at":"2026-07-05T00:29:41.215504+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1911.07140","created_at":"2026-07-05T00:29:41.215504+00:00"},{"alias_kind":"pith_short_12","alias_value":"FLIEIUECVESB","created_at":"2026-07-05T00:29:41.215504+00:00"},{"alias_kind":"pith_short_16","alias_value":"FLIEIUECVESBNADL","created_at":"2026-07-05T00:29:41.215504+00:00"},{"alias_kind":"pith_short_8","alias_value":"FLIEIUEC","created_at":"2026-07-05T00:29:41.215504+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":2,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.22999","citing_title":"Black-Box Continual Learning for Vision-Language Models","ref_index":42,"is_internal_anchor":false},{"citing_arxiv_id":"2605.12792","citing_title":"SoK: A Comprehensive Analysis of the Current Status of Neural Tangent Generalization Attacks with Research Directions","ref_index":44,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/FLIEIUECVESBNADL5WTSQQF6VC","json":"https://pith.science/pith/FLIEIUECVESBNADL5WTSQQF6VC.json","graph_json":"https://pith.science/api/pith-number/FLIEIUECVESBNADL5WTSQQF6VC/graph.json","events_json":"https://pith.science/api/pith-number/FLIEIUECVESBNADL5WTSQQF6VC/events.json","paper":"https://pith.science/paper/FLIEIUEC"},"agent_actions":{"view_html":"https://pith.science/pith/FLIEIUECVESBNADL5WTSQQF6VC","download_json":"https://pith.science/pith/FLIEIUECVESBNADL5WTSQQF6VC.json","view_paper":"https://pith.science/paper/FLIEIUEC","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=1911.07140&json=true","fetch_graph":"https://pith.science/api/pith-number/FLIEIUECVESBNADL5WTSQQF6VC/graph.json","fetch_events":"https://pith.science/api/pith-number/FLIEIUECVESBNADL5WTSQQF6VC/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/FLIEIUECVESBNADL5WTSQQF6VC/action/timestamp_anchor","attest_storage":"https://pith.science/pith/FLIEIUECVESBNADL5WTSQQF6VC/action/storage_attestation","attest_author":"https://pith.science/pith/FLIEIUECVESBNADL5WTSQQF6VC/action/author_attestation","sign_citation":"https://pith.science/pith/FLIEIUECVESBNADL5WTSQQF6VC/action/citation_signature","submit_replication":"https://pith.science/pith/FLIEIUECVESBNADL5WTSQQF6VC/action/replication_record"}},"created_at":"2026-07-05T00:29:41.215504+00:00","updated_at":"2026-07-05T00:29:41.215504+00:00"}