{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,28]],"date-time":"2026-01-28T22:09:08Z","timestamp":1769638148875,"version":"3.49.0"},"reference-count":39,"publisher":"Springer Science and Business Media LLC","issue":"12","license":[{"start":{"date-parts":[[2020,10,29]],"date-time":"2020-10-29T00:00:00Z","timestamp":1603929600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2020,10,29]],"date-time":"2020-10-29T00:00:00Z","timestamp":1603929600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61673201"],"award-info":[{"award-number":["61673201"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["1719097"],"award-info":[{"award-number":["1719097"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Mach Learn"],"published-print":{"date-parts":[[2020,12]]},"DOI":"10.1007\/s10994-020-05916-1","type":"journal-article","created":{"date-parts":[[2020,10,29]],"date-time":"2020-10-29T21:02:35Z","timestamp":1604005355000},"page":"2349-2368","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":8,"title":["Spanning attack: reinforce black-box attacks with unlabeled data"],"prefix":"10.1007","volume":"109","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-9437-6898","authenticated-orcid":false,"given":"Lu","family":"Wang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Huan","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jinfeng","family":"Yi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Cho-Jui","family":"Hsieh","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yuan","family":"Jiang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2020,10,29]]},"reference":[{"key":"5916_CR1","doi-asserted-by":"publisher","first-page":"317","DOI":"10.1016\/j.patcog.2018.07.023","volume":"84","author":"B Biggio","year":"2018","unstructured":"Biggio, B., & Roli, F. (2018). Wild patterns: Ten years after the rise of adversarial machine learning. Pattern Recognition, 84, 317\u2013331.","journal-title":"Pattern Recognition"},{"key":"5916_CR2","unstructured":"Brendel, W., Rauber, J., & Bethge, M. (2018). Decision-based adversarial attacks: Reliable attacks against black-box machine learning models. In International conference on learning representations (ICLR)."},{"key":"5916_CR3","doi-asserted-by":"crossref","unstructured":"Brunner, T., Diehl, F., Truong-Le, M., & Knoll, A. (2018). Guessing smart: Biased sampling for efficient black-box adversarial attacks. In IEEE international conference on computer vision (ICCV) (pp. 4958\u20134966).","DOI":"10.1109\/ICCV.2019.00506"},{"key":"5916_CR4","doi-asserted-by":"crossref","unstructured":"Carlini, N., & Wagner, D. (2017). Towards evaluating the robustness of neural networks. In IEEE symposium on security and privacy (SP) (pp. 39\u201357).","DOI":"10.1109\/SP.2017.49"},{"key":"5916_CR5","doi-asserted-by":"crossref","unstructured":"Chen, J., Jordan, M. I., & Wainwright, M. J. (2019). Hopskipjumpattack: A query-efficient decision-based attack. CoRR abs\/1904.02144.","DOI":"10.1109\/SP40000.2020.00045"},{"key":"5916_CR6","unstructured":"Chen, H., Zhang, H., Boning, D., & Hsieh, C. J. (2019). Robust decision trees against adversarial examples. In International conference on machine learning (ICML) (pp. 1122\u20131131)."},{"key":"5916_CR7","doi-asserted-by":"crossref","unstructured":"Chen, P. Y., Zhang, H., Sharma, Y., Yi, J., & Hsieh, C. J. (2017). ZOO: Zeroth order optimization based black-box attacks to deep neural networks without training substitute models. In ACM conference on computer and communications security (CCS) workshop on artificial intelligence and security (AISec) (pp. 15\u201326).","DOI":"10.1145\/3128572.3140448"},{"key":"5916_CR8","volume-title":"Linear algebra: Theory and applications","author":"W Cheney","year":"2010","unstructured":"Cheney, W., & Kincaid, D. R. (2010). Linear algebra: Theory and applications. Washington, DC: The Saylor Foundation."},{"key":"5916_CR9","unstructured":"Cheng, S., Dong, Y., Pang, T., Su, H., & Zhu, J. (2019). Improving black-box adversarial attacks with a transfer-based prior. In Advances in neural information processing systems (NeurIPS)."},{"key":"5916_CR10","unstructured":"Cheng, M., Le, T., Chen, P. Y., Yi, J., Zhang, H., & Hsieh, C. J. (2019). Query-efficient hard-label black-box attack: An optimization-based approach. In International conference on learning representations (ICLR)."},{"key":"5916_CR11","unstructured":"Cheng, M., Singh, S., Chen, P. Y., Liu, S., & Hsieh, C. J. (2020) Sign-opt: A query-efficient hard-label adversarial attack. In International conference on learning representations (ICLR)."},{"issue":"3","key":"5916_CR12","first-page":"273","volume":"20","author":"C Cortes","year":"1995","unstructured":"Cortes, C., & Vapnik, V. (1995). Support-vector networks. Machine Learning, 20(3), 273\u2013297.","journal-title":"Machine Learning"},{"key":"5916_CR13","doi-asserted-by":"crossref","unstructured":"Deng, J., Dong, W., Socher, R., Li, L. J., Li, K., & Fei-Fei, L. (2009) Imagenet: A large-scale hierarchical image database. In IEEE conference on computer vision and pattern recognition (CVPR) (pp. 248\u2013255).","DOI":"10.1109\/CVPR.2009.5206848"},{"issue":"3","key":"5916_CR14","doi-asserted-by":"publisher","first-page":"481","DOI":"10.1007\/s10994-017-5663-3","volume":"107","author":"A Fawzi","year":"2018","unstructured":"Fawzi, A., Fawzi, O., & Frossard, P. (2018). Analysis of classifiers\u2019 robustness to adversarial perturbations. Machine Learning, 107(3), 481\u2013508.","journal-title":"Machine Learning"},{"key":"5916_CR15","unstructured":"Goodfellow, I. J., Shlens, J., & Szegedy, C. (2015). Explaining and harnessing adversarial examples. In International conference on learning representations (ICLR)."},{"key":"5916_CR16","doi-asserted-by":"crossref","unstructured":"He, K., Zhang, X., Ren, S., & Sun, J. (2016). Deep residual learning for image recognition. In IEEE conference on computer vision and pattern recognition (CVPR) (pp. 770\u2013778).","DOI":"10.1109\/CVPR.2016.90"},{"key":"5916_CR17","unstructured":"Hodosh, M., Young, P., & Hockenmaier, J. C. (2015). Framing image description as a ranking task: data, models and evaluation metrics. In International conference on artificial intelligence (IJCAI) (pp. 4188\u20134192)."},{"key":"5916_CR18","doi-asserted-by":"crossref","unstructured":"Huang, G., Liu, Z., van\u00a0der Maaten, L., & Weinberger, K. Q. (2017). Densely connected convolutional networks. In IEEE conference on computer vision and pattern recognition (CVPR) (pp. 2261\u20132269).","DOI":"10.1109\/CVPR.2017.243"},{"key":"5916_CR19","unstructured":"Ilyas, A., Engstrom, L., Athalye, A., & Lin, J. (2018) Black-box adversarial attacks with limited queries and information. In International conference on machine learning (ICML) (pp. 2142\u20132151)."},{"key":"5916_CR20","unstructured":"Ilyas, A., Engstrom, L., & Madry, A. (2019) Prior convictions: Black-box adversarial attacks with bandits and priors. In International conference on learning representations (ICLR)."},{"key":"5916_CR21","unstructured":"Kantchelian, A., Tygar, J., & Joseph, A. (2016). Evasion and hardening of tree ensemble classifiers. In International conference on machine learning (ICML) (pp. 2387\u20132396)."},{"key":"5916_CR22","doi-asserted-by":"crossref","unstructured":"Katz, G., Barrett, C., Dill, D. L., Julian, K., & Kochenderfer, M. J. (2017). Reluplex: An efficient SMT solver for verifying deep neural networks. In International conference on computer aided verification (pp. 97\u2013117).","DOI":"10.1007\/978-3-319-63387-9_5"},{"key":"5916_CR23","unstructured":"Liu, S., Chen, P. Y., Chen, X., & Hong, M. (2019). signSGD via zeroth-order oracle. In International conference on learning representations (ICLR)."},{"key":"5916_CR24","unstructured":"Liu, Y., Chen, X., Liu, C., & Song, D. (2017) Delving into transferable adversarial examples and black-box attacks. In International conference on learning representations (ICLR)."},{"key":"5916_CR25","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., & Vladu, A. (2018) Towards deep learning models resistant to adversarial attacks. In International conference on learning representations (ICLR)."},{"issue":"2","key":"5916_CR26","doi-asserted-by":"publisher","first-page":"527","DOI":"10.1007\/s10208-015-9296-2","volume":"17","author":"Y Nesterov","year":"2017","unstructured":"Nesterov, Y., & Spokoiny, V. G. (2017). Random gradient-free minimization of convex functions. Foundations of Computational Mathematics, 17(2), 527\u2013566.","journal-title":"Foundations of Computational Mathematics"},{"key":"5916_CR27","unstructured":"Papernot, N., McDaniel, P. D., & Goodfellow, I.J. (2016) Transferability in machine learning: From phenomena to black-box attacks using adversarial samples. CoRR abs\/1605.07277."},{"key":"5916_CR28","doi-asserted-by":"crossref","unstructured":"Papernot, N., McDaniel, P., Goodfellow, I., Jha, S., Celik, Z. B., & Swami, A. (2017). Practical black-box attacks against machine learning. In Asia conference on computer and communications security (pp. 506\u2013519).","DOI":"10.1145\/3052973.3053009"},{"key":"5916_CR29","unstructured":"Simonyan, K., & Zisserman, A. (2015). Very deep convolutional networks for large-scale image recognition. In International conference on learning representations (ICLR)."},{"key":"5916_CR30","unstructured":"Steiner, B., DeVito, Z., Chintala, S., Gross, S., Paszke, A., Massa, F., Lerer, A., Chanan, G., Lin, Z., Yang, E., Desmaison, A., Tejani, A., Kopf, A., Bradbury, J., Antiga, L., Raison, M., Gimelshein, N., Chilamkurthy, S., Killeen, T., Fang, L., & Bai, J. (2019) Pytorch: An imperative style, high-performance deep learning library. In Advances in neural information processing systems (NeurIPS) (pp. 8024\u20138035)."},{"key":"5916_CR31","doi-asserted-by":"crossref","unstructured":"Stutz, D., Hein, M., & Schiele, B. (2019). Disentangling adversarial robustness and generalization. In IEEE conference on computer vision and pattern recognition (CVPR) (pp. 6976\u20136987).","DOI":"10.1109\/CVPR.2019.00714"},{"key":"5916_CR32","doi-asserted-by":"crossref","unstructured":"Su, D., Zhang, H., Chen, H., Yi, J., Chen, P. Y., & Gao, Y. (2018). Is robustness the cost of accuracy?\u2014A comprehensive study on the robustness of 18 deep image classification models. In European conference on computer vision (ECCV) (pp. 644\u2013661).","DOI":"10.1007\/978-3-030-01258-8_39"},{"key":"5916_CR33","unstructured":"Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I. J., & Fergus, R. (2014). Intriguing properties of neural networks. In International conference on learning representations (ICLR)."},{"key":"5916_CR34","doi-asserted-by":"publisher","first-page":"742","DOI":"10.1609\/aaai.v33i01.3301742","volume":"33","author":"CC Tu","year":"2019","unstructured":"Tu, C. C., Ting, P., Chen, P. Y., Liu, S., Zhang, H., Yi, J., et al. (2019). Autozoom: Autoencoder-based zeroth order optimization method for attacking black-box neural networks. AAAI Conference on Artificial Intelligence (AAAI), 33, 742\u2013749.","journal-title":"AAAI Conference on Artificial Intelligence (AAAI)"},{"key":"5916_CR35","unstructured":"Uesato, J., O\u2019Donoghue, B., Kohli, P., van\u00a0den Oord, A. (2018). Adversarial risk and the dangers of evaluating against weak attacks. In International conference on machine learning (ICML) (pp. 5025\u20135034)."},{"key":"5916_CR36","unstructured":"Wang, Y., Du, S. S., Balakrishnan, S., Singh, A. (2017). Stochastic zeroth-order optimization in high dimensions. In International conference on artificial intelligence and statistics (AISTATS) (pp. 1356\u20131365)."},{"key":"5916_CR37","unstructured":"Wang, L., Liu, X., Yi, J., Jiang, Y., & Hsieh, C. J. (2020). Provably robust metric learning. CoRR abs\/2006.07024."},{"key":"5916_CR38","unstructured":"Wang, L., Liu, X., Yi, J., Zhou, Z. H., & Hsieh, C. J. (2019) Evaluating the robustness of nearest neighbor classifiers: A primal-dual perspective. CoRR abs\/1906.03972."},{"key":"5916_CR39","unstructured":"Yan, Z., Guo, Y., Zhang, C. (2019). Subspace attack: Exploiting promising subspaces for query-efficient black-box attacks. In Advances in neural information processing systems (NeurIPS)."}],"container-title":["Machine Learning"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10994-020-05916-1.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10994-020-05916-1\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10994-020-05916-1.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,10,29]],"date-time":"2021-10-29T00:03:48Z","timestamp":1635465828000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10994-020-05916-1"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,10,29]]},"references-count":39,"journal-issue":{"issue":"12","published-print":{"date-parts":[[2020,12]]}},"alternative-id":["5916"],"URL":"https:\/\/doi.org\/10.1007\/s10994-020-05916-1","relation":{},"ISSN":["0885-6125","1573-0565"],"issn-type":[{"value":"0885-6125","type":"print"},{"value":"1573-0565","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,10,29]]},"assertion":[{"value":"16 April 2020","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"1 August 2020","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"19 September 2020","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"29 October 2020","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Compliance with ethical standards"}},{"value":"The authors declare that they have no conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}