REVIEW 4 cited by
A Survey of Black-Box Adversarial Attacks on Computer Vision Models
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
read the original abstract
Machine learning has seen tremendous advances in the past few years, which has lead to deep learning models being deployed in varied applications of day-to-day life. Attacks on such models using perturbations, particularly in real-life scenarios, pose a severe challenge to their applicability, pushing research into the direction which aims to enhance the robustness of these models. After the introduction of these perturbations by Szegedy et al. [1], significant amount of research has focused on the reliability of such models, primarily in two aspects - white-box, where the adversary has access to the targeted model and related parameters; and the black-box, which resembles a real-life scenario with the adversary having almost no knowledge of the model to be attacked. To provide a comprehensive security cover, it is essential to identify, study, and build defenses against such attacks. Hence, in this paper, we propose to present a comprehensive comparative study of various black-box adversarial attacks and defense techniques.
Forward citations
Cited by 4 Pith papers
-
AdvNav: Behavior-Guided Black-Box Adversarial Attacks on Vision-Language Navigation
AdvNav is a gradient-free attack that overlays Perlin noise on a VLN agent's camera and uses behavior feedback plus genetic search, breaking 49.70-87.30% of successful R2R navigations.
-
Attacking interpretable NLP systems
AdvChar is a character-level black-box attack that uses interpreter importance scores to pick tokens, fooling NLP classifiers while keeping post-hoc explanations similar.
-
Amnesia as a Catalyst for Enhancing Black Box Pixel Attacks in Image Classification and Object Detection
A reinforcement-learning attack using a memory-and-reset 'Forget' process fools classifiers and object detectors by modifying fewer than 0.1% of pixels, with fewer queries than prior query-based attacks.
-
Consensus-based optimization for closed-box adversarial attacks and a connection to evolution strategies
Consensus-based optimization matches or beats natural evolution strategies as a closed-box adversarial attack method in easier attack scenarios, and consensus hopping is shown to be a gradient-descent-like limit of CBO.
Discussion (0). Continue with ORCID to comment.