{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2017:VD7WSAYJTFPOUKECPON3C2OTIZ","short_pith_number":"pith:VD7WSAYJ","schema_version":"1.0","canonical_sha256":"a8ff690309995eea28827b9bb169d3467c1f7d7e4658e298fc490065fee65a32","source":{"kind":"arxiv","id":"1712.09491","version":1},"attestation_state":"computed","paper":{"title":"Exploring the Space of Black-box Attacks on Deep Neural Networks","license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","headline":"","cross_cats":["cs.CR","cs.CV"],"primary_cat":"cs.LG","authors_text":"Arjun Nitin Bhagoji, Bo Li, Dawn Song, Warren He","submitted_at":"2017-12-27T04:39:02Z","abstract_excerpt":"Existing black-box attacks on deep neural networks (DNNs) so far have largely focused on transferability, where an adversarial instance generated for a locally trained model can \"transfer\" to attack other learning models. In this paper, we propose novel Gradient Estimation black-box attacks for adversaries with query access to the target model's class probabilities, which do not rely on transferability. We also propose strategies to decouple the number of queries required to generate each adversarial sample from the dimensionality of the input. An iterative variant of our attack achieves close"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"1712.09491","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.LG","submitted_at":"2017-12-27T04:39:02Z","cross_cats_sorted":["cs.CR","cs.CV"],"title_canon_sha256":"74ce1e340e102b37faea440987a6df35063ea24d187459d02ab5568b2efe039a","abstract_canon_sha256":"5a7ffd383b1e8479f81c53e25f0e70c1e7c36a84e1bfb42d45e18e0f5474dedb"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:27:08.216488Z","signature_b64":"Xobl2Z5IuKWl1wuZl9/HCs/eEKikN+LqptyaJDFd7WqUY6YYmvecipUe0dK1y+55/5rfOAEhU2mRqgkWEKYLCg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"a8ff690309995eea28827b9bb169d3467c1f7d7e4658e298fc490065fee65a32","last_reissued_at":"2026-05-18T00:27:08.215953Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:27:08.215953Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Exploring the Space of Black-box Attacks on Deep Neural Networks","license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","headline":"","cross_cats":["cs.CR","cs.CV"],"primary_cat":"cs.LG","authors_text":"Arjun Nitin Bhagoji, Bo Li, Dawn Song, Warren He","submitted_at":"2017-12-27T04:39:02Z","abstract_excerpt":"Existing black-box attacks on deep neural networks (DNNs) so far have largely focused on transferability, where an adversarial instance generated for a locally trained model can \"transfer\" to attack other learning models. In this paper, we propose novel Gradient Estimation black-box attacks for adversaries with query access to the target model's class probabilities, which do not rely on transferability. We also propose strategies to decouple the number of queries required to generate each adversarial sample from the dimensionality of the input. An iterative variant of our attack achieves close"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1712.09491","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"1712.09491","created_at":"2026-05-18T00:27:08.216035+00:00"},{"alias_kind":"arxiv_version","alias_value":"1712.09491v1","created_at":"2026-05-18T00:27:08.216035+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1712.09491","created_at":"2026-05-18T00:27:08.216035+00:00"},{"alias_kind":"pith_short_12","alias_value":"VD7WSAYJTFPO","created_at":"2026-05-18T12:31:49.984773+00:00"},{"alias_kind":"pith_short_16","alias_value":"VD7WSAYJTFPOUKEC","created_at":"2026-05-18T12:31:49.984773+00:00"},{"alias_kind":"pith_short_8","alias_value":"VD7WSAYJ","created_at":"2026-05-18T12:31:49.984773+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":2,"internal_anchor_count":2,"sample":[{"citing_arxiv_id":"1907.00374","citing_title":"Fooling a Real Car with Adversarial Traffic Signs","ref_index":22,"is_internal_anchor":true},{"citing_arxiv_id":"2605.12792","citing_title":"SoK: A Comprehensive Analysis of the Current Status of Neural Tangent Generalization Attacks with Research Directions","ref_index":6,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/VD7WSAYJTFPOUKECPON3C2OTIZ","json":"https://pith.science/pith/VD7WSAYJTFPOUKECPON3C2OTIZ.json","graph_json":"https://pith.science/api/pith-number/VD7WSAYJTFPOUKECPON3C2OTIZ/graph.json","events_json":"https://pith.science/api/pith-number/VD7WSAYJTFPOUKECPON3C2OTIZ/events.json","paper":"https://pith.science/paper/VD7WSAYJ"},"agent_actions":{"view_html":"https://pith.science/pith/VD7WSAYJTFPOUKECPON3C2OTIZ","download_json":"https://pith.science/pith/VD7WSAYJTFPOUKECPON3C2OTIZ.json","view_paper":"https://pith.science/paper/VD7WSAYJ","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=1712.09491&json=true","fetch_graph":"https://pith.science/api/pith-number/VD7WSAYJTFPOUKECPON3C2OTIZ/graph.json","fetch_events":"https://pith.science/api/pith-number/VD7WSAYJTFPOUKECPON3C2OTIZ/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/VD7WSAYJTFPOUKECPON3C2OTIZ/action/timestamp_anchor","attest_storage":"https://pith.science/pith/VD7WSAYJTFPOUKECPON3C2OTIZ/action/storage_attestation","attest_author":"https://pith.science/pith/VD7WSAYJTFPOUKECPON3C2OTIZ/action/author_attestation","sign_citation":"https://pith.science/pith/VD7WSAYJTFPOUKECPON3C2OTIZ/action/citation_signature","submit_replication":"https://pith.science/pith/VD7WSAYJTFPOUKECPON3C2OTIZ/action/replication_record"}},"created_at":"2026-05-18T00:27:08.216035+00:00","updated_at":"2026-05-18T00:27:08.216035+00:00"}