{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2021:ODN5DKRZDB2SKPFANEB5RAXZT3","short_pith_number":"pith:ODN5DKRZ","schema_version":"1.0","canonical_sha256":"70dbd1aa391875253ca06903d882f99eff690200966610beb899179256e388da","source":{"kind":"arxiv","id":"2104.11470","version":2},"attestation_state":"computed","paper":{"title":"Random Noise Defense Against Query-Based Black-Box Attacks","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.LG","authors_text":"Baoyuan Wu, Hongyuan Zha, Yanbo Fan, Zeyu Qin","submitted_at":"2021-04-23T08:39:41Z","abstract_excerpt":"The query-based black-box attacks have raised serious threats to machine learning models in many real applications. In this work, we study a lightweight defense method, dubbed Random Noise Defense (RND), which adds proper Gaussian noise to each query. We conduct the theoretical analysis about the effectiveness of RND against query-based black-box attacks and the corresponding adaptive attacks. Our theoretical results reveal that the defense performance of RND is determined by the magnitude ratio between the noise induced by RND and the noise added by the attackers for gradient estimation or lo"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2104.11470","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2021-04-23T08:39:41Z","cross_cats_sorted":["cs.CR"],"title_canon_sha256":"d74f6fbaa1e46053e17a6d8744872882861f4319ea9e80942e7e2ab7c00b461d","abstract_canon_sha256":"28d35d24c417d70cef48663a8717416be2d626f4f30565ccc4854516752b089e"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T03:27:30.923776Z","signature_b64":"G5iL5LWhdGiiD8EDlhl7rmbYAwSTWqcT8UXS7A7c5rA8oNCjM86P2dJeY7+IuqvV4X2gICBDdza/uWMYT30LCA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"70dbd1aa391875253ca06903d882f99eff690200966610beb899179256e388da","last_reissued_at":"2026-07-05T03:27:30.923308Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T03:27:30.923308Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Random Noise Defense Against Query-Based Black-Box Attacks","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.LG","authors_text":"Baoyuan Wu, Hongyuan Zha, Yanbo Fan, Zeyu Qin","submitted_at":"2021-04-23T08:39:41Z","abstract_excerpt":"The query-based black-box attacks have raised serious threats to machine learning models in many real applications. In this work, we study a lightweight defense method, dubbed Random Noise Defense (RND), which adds proper Gaussian noise to each query. We conduct the theoretical analysis about the effectiveness of RND against query-based black-box attacks and the corresponding adaptive attacks. Our theoretical results reveal that the defense performance of RND is determined by the magnitude ratio between the noise induced by RND and the noise added by the attackers for gradient estimation or lo"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2104.11470","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2104.11470/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2104.11470","created_at":"2026-07-05T03:27:30.923381+00:00"},{"alias_kind":"arxiv_version","alias_value":"2104.11470v2","created_at":"2026-07-05T03:27:30.923381+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2104.11470","created_at":"2026-07-05T03:27:30.923381+00:00"},{"alias_kind":"pith_short_12","alias_value":"ODN5DKRZDB2S","created_at":"2026-07-05T03:27:30.923381+00:00"},{"alias_kind":"pith_short_16","alias_value":"ODN5DKRZDB2SKPFA","created_at":"2026-07-05T03:27:30.923381+00:00"},{"alias_kind":"pith_short_8","alias_value":"ODN5DKRZ","created_at":"2026-07-05T03:27:30.923381+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.21592","citing_title":"Enhancing Stateful Detection of Adversarial Attacks with Soft-labels' Temporality and Robust Similarity Approximations","ref_index":21,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/ODN5DKRZDB2SKPFANEB5RAXZT3","json":"https://pith.science/pith/ODN5DKRZDB2SKPFANEB5RAXZT3.json","graph_json":"https://pith.science/api/pith-number/ODN5DKRZDB2SKPFANEB5RAXZT3/graph.json","events_json":"https://pith.science/api/pith-number/ODN5DKRZDB2SKPFANEB5RAXZT3/events.json","paper":"https://pith.science/paper/ODN5DKRZ"},"agent_actions":{"view_html":"https://pith.science/pith/ODN5DKRZDB2SKPFANEB5RAXZT3","download_json":"https://pith.science/pith/ODN5DKRZDB2SKPFANEB5RAXZT3.json","view_paper":"https://pith.science/paper/ODN5DKRZ","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2104.11470&json=true","fetch_graph":"https://pith.science/api/pith-number/ODN5DKRZDB2SKPFANEB5RAXZT3/graph.json","fetch_events":"https://pith.science/api/pith-number/ODN5DKRZDB2SKPFANEB5RAXZT3/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/ODN5DKRZDB2SKPFANEB5RAXZT3/action/timestamp_anchor","attest_storage":"https://pith.science/pith/ODN5DKRZDB2SKPFANEB5RAXZT3/action/storage_attestation","attest_author":"https://pith.science/pith/ODN5DKRZDB2SKPFANEB5RAXZT3/action/author_attestation","sign_citation":"https://pith.science/pith/ODN5DKRZDB2SKPFANEB5RAXZT3/action/citation_signature","submit_replication":"https://pith.science/pith/ODN5DKRZDB2SKPFANEB5RAXZT3/action/replication_record"}},"created_at":"2026-07-05T03:27:30.923381+00:00","updated_at":"2026-07-05T03:27:30.923381+00:00"}