Pith. sign in

REVIEW 1 cited by

There are No Bit Parts for Sign Bits in Black-Box Attacks

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1902.06894 v4 pith:ZE2EZ6BM submitted 2019-02-19 cs.LG cs.CRstat.ML

classification cs.LGcs.CRstat.ML
keywords algorithmattacksblack-boxmodelattackqueriesadversarialdatasets
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
abstract

We present a black-box adversarial attack algorithm which sets new state-of-the-art model evasion rates for query efficiency in the $\ell_\infty$ and $\ell_2$ metrics, where only loss-oracle access to the model is available. On two public black-box attack challenges, the algorithm achieves the highest evasion rate, surpassing all of the submitted attacks. Similar performance is observed on a model that is secure against substitute-model attacks. For standard models trained on the MNIST, CIFAR10, and IMAGENET datasets, averaged over the datasets and metrics, the algorithm is 3.8x less failure-prone, and spends in total 2.5x fewer queries than the current state-of-the-art attacks combined given a budget of 10, 000 queries per attack attempt. Notably, it requires no hyperparameter tuning or any data/time-dependent prior. The algorithm exploits a new approach, namely sign-based rather than magnitude-based gradient estimation. This shifts the estimation from continuous to binary black-box optimization. With three properties of the directional derivative, we examine three approaches to adversarial attacks. This yields a superior algorithm breaking a standard MNIST model using just 12 queries on average!

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Consensus-based optimization for closed-box adversarial attacks and a connection to evolution strategies

    math.OC 2025-06 conditional novelty 5.0 of 10

    Consensus-based optimization matches or beats natural evolution strategies as a closed-box adversarial attack method in easier attack scenarios, and consensus hopping is shown to be a gradient-descent-like limit of CBO.

Pith tools