{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,13]],"date-time":"2026-06-13T05:44:42Z","timestamp":1781329482217,"version":"3.54.1"},"publisher-location":"New York, NY, USA","reference-count":32,"publisher":"ACM","license":[{"start":{"date-parts":[[2019,7,13]],"date-time":"2019-07-13T00:00:00Z","timestamp":1562976000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100006754","name":"Army Research Laboratory","doi-asserted-by":"publisher","award":["W911NF-16-3-0001,"],"award-info":[{"award-number":["W911NF-16-3-0001,"]}],"id":[{"id":"10.13039\/100006754","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["OAC-1640813, CNS-1705135"],"award-info":[{"award-number":["OAC-1640813, CNS-1705135"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2019,7,13]]},"DOI":"10.1145\/3321707.3321749","type":"proceedings-article","created":{"date-parts":[[2019,7,3]],"date-time":"2019-07-03T13:48:04Z","timestamp":1562161684000},"page":"1111-1119","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":162,"title":["GenAttack"],"prefix":"10.1145","author":[{"given":"Moustafa","family":"Alzantot","sequence":"first","affiliation":[{"name":"UCLA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yash","family":"Sharma","sequence":"additional","affiliation":[{"name":"Cooper Union"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Supriyo","family":"Chakraborty","sequence":"additional","affiliation":[{"name":"IBM Research"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Huan","family":"Zhang","sequence":"additional","affiliation":[{"name":"UCLA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Cho-Jui","family":"Hsieh","sequence":"additional","affiliation":[{"name":"UCLA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mani B.","family":"Srivastava","sequence":"additional","affiliation":[{"name":"UCLA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2019,7,13]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Machine Deception Workshop, Neural Information Processing Systems (NIPS) 2017","author":"Alzantot Moustafa","year":"2017"},{"key":"e_1_3_2_1_2_1","volume-title":"Generating Natural Language Adversarial Examples. EMNLP: Conference on Empirical Methods in Natural Language Processing","author":"Alzantot Moustafa","year":"2018"},{"key":"e_1_3_2_1_3_1","unstructured":"A. Athalye N. Carlini and D. Wagner. 2018. Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples. arXiv preprint arXiv:1802.00420 (2018).  A. Athalye N. Carlini and D. Wagner. 2018. Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples. arXiv preprint arXiv:1802.00420 (2018)."},{"key":"e_1_3_2_1_4_1","unstructured":"A. Athalye L. Engstrom A. Ilyas and K. Kwok. 2017. Synthesizing robust adversarial examples. arXiv preprint arXiv:1707.07397 (2017).  A. Athalye L. Engstrom A. Ilyas and K. Kwok. 2017. Synthesizing robust adversarial examples. arXiv preprint arXiv:1707.07397 (2017)."},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1142\/S0218001496000438"},{"key":"e_1_3_2_1_6_1","volume-title":"International Conference on Learning Representations (ICLR)","author":"Brendel Wieland","year":"2018"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"crossref","unstructured":"N. Carlini and D. Wagner. 2017. Towards evaluating the robustness of neural networks. arXiv preprint arXiv:1608.04644 (2017).  N. Carlini and D. Wagner. 2017. Towards evaluating the robustness of neural networks. arXiv preprint arXiv:1608.04644 (2017).","DOI":"10.1109\/SP.2017.49"},{"key":"e_1_3_2_1_8_1","volume-title":"EAD: Elasticnet attacks to deep neural networks via adversarial examples. arXiv preprint arXiv:1709.0414","author":"Chen P. Y.","year":"2017"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140448"},{"key":"e_1_3_2_1_10_1","volume-title":"Computer Vision and Pattern Recognition, 2009. CVPR 2009. IEEE Conference on. IEEE, 248--255","author":"Deng J."},{"key":"e_1_3_2_1_11_1","unstructured":"I. Goodfellow J. Shlens and C. Szegedy. 2014. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 (2014).  I. Goodfellow J. Shlens and C. Szegedy. 2014. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 (2014)."},{"key":"e_1_3_2_1_12_1","unstructured":"S. Gu and L. Rigazio. 2014. Towards deep neural network architectures robust to adversarial examples. arXiv preprint arXiv:1412.5068 (2014).  S. Gu and L. Rigazio. 2014. Towards deep neural network architectures robust to adversarial examples. arXiv preprint arXiv:1412.5068 (2014)."},{"key":"e_1_3_2_1_13_1","volume-title":"Countering adversarial images using input transformations. arXiv preprint arXiv:1711.00117","author":"Guo C.","year":"2017"},{"key":"e_1_3_2_1_14_1","volume":"201","author":"Ilyas A.","journal-title":"J. Lin."},{"key":"e_1_3_2_1_15_1","volume":"201","author":"Kingma D.","journal-title":"J. Ba."},{"key":"e_1_3_2_1_16_1","unstructured":"A. Kurakin I. Goodfellow and S. Bengio. 2016. Adversarial examples in the physical world. arXiv preprint arXiv:1607.02533 (2016).  A. Kurakin I. Goodfellow and S. Bengio. 2016. Adversarial examples in the physical world. arXiv preprint arXiv:1607.02533 (2016)."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"crossref","unstructured":"A. Kurakin I. Goodfellow S. Bengio Y. Dong F. Liao M. Liang T. Pang J. Zhu X. Hu C. Xie J. Wang Z. Zhang Z. Ren A. Yuille S. Huang Y. Zhao Y. Zhao Z. Han J Long Y. Berdibekov T. Akiba S. Tokui and M. Abe. 2018. Adversarial attacks and defences competition. arXiv preprint arXiv:1804.00097 (2018).  A. Kurakin I. Goodfellow S. Bengio Y. Dong F. Liao M. Liang T. Pang J. Zhu X. Hu C. Xie J. Wang Z. Zhang Z. Ren A. Yuille S. Huang Y. Zhao Y. Zhao Z. Han J Long Y. Berdibekov T. Akiba S. Tokui and M. Abe. 2018. Adversarial attacks and defences competition. arXiv preprint arXiv:1804.00097 (2018).","DOI":"10.1007\/978-3-319-94042-7_11"},{"key":"e_1_3_2_1_18_1","volume-title":"International Conference on Learning Representations (ICLR)","author":"Liu Yanpei","year":"2018"},{"key":"e_1_3_2_1_19_1","unstructured":"P. H. Lu P. Y. Chen K. C. Chen and C. M. Yu. 2018. On the limitation of MagNet defense against L1-based adversarial examples. arXiv preprint arXiv:1805.00310 (2018).  P. H. Lu P. Y. Chen K. C. Chen and C. M. Yu. 2018. On the limitation of MagNet defense against L1-based adversarial examples. arXiv preprint arXiv:1805.00310 (2018)."},{"key":"e_1_3_2_1_20_1","unstructured":"A. Madry A. Makelov L. Schmidt D. Tsipras and A. Vladu. 2017. Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083 (2017).  A. Madry A. Makelov L. Schmidt D. Tsipras and A. Vladu. 2017. Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083 (2017)."},{"key":"e_1_3_2_1_21_1","volume-title":"Proceedings of 2016 IEEE Conference on Computer Vision and Pattern Recognition (CVPR).","author":"Moosavi-Dezfooli S."},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"e_1_3_2_1_23_1","volume-title":"International Conference on Learning Representations (ICLR)","author":"Schott Lukas","year":"2019"},{"key":"e_1_3_2_1_24_1","unstructured":"Y. Sharma and P. Y. Chen. 2017. Attacking the Madry defense model with L1-based adversarial examples. arXiv preprint arXiv:1710.10733 (2017).  Y. Sharma and P. Y. Chen. 2017. Attacking the Madry defense model with L1-based adversarial examples. arXiv preprint arXiv:1710.10733 (2017)."},{"key":"e_1_3_2_1_25_1","unstructured":"Y. Sharma and P. Y. Chen. 2018. Bypassing feature squeezing by increasing adversary strength. arXiv preprint arXiv:1803.09868 (2018).  Y. Sharma and P. Y. Chen. 2018. Bypassing feature squeezing by increasing adversary strength. arXiv preprint arXiv:1803.09868 (2018)."},{"key":"e_1_3_2_1_26_1","volume-title":"CAAD 2018: Generating Transferable Adversarial Examples. arXiv preprint arXiv:1810","author":"Sharma Y.","year":"2018"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01258-8_39"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"crossref","unstructured":"C. Szegedy W. Liu Y. Jia P. Sermanet S. Reed D. Anguelov D. Erhan V. Vanhoucke and A. Rabinovich. 2015. Going deeper with convolutions. CVPR.  C. Szegedy W. Liu Y. Jia P. Sermanet S. Reed D. Anguelov D. Erhan V. Vanhoucke and A. Rabinovich. 2015. Going deeper with convolutions. CVPR.","DOI":"10.1109\/CVPR.2015.7298594"},{"key":"e_1_3_2_1_29_1","unstructured":"C. Szegedy W. Zaremba I. Sutskever J. Bruna D. Erhan and I. Goodfellow. 2013. Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199 (2013).  C. Szegedy W. Zaremba I. Sutskever J. Bruna D. Erhan and I. Goodfellow. 2013. Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199 (2013)."},{"key":"e_1_3_2_1_30_1","volume-title":"Ensemble adversarial training: Attacks and Defenses. arXiv preprint arXiv:1705.07204","author":"Tram\u00e9r F.","year":"2017"},{"key":"e_1_3_2_1_31_1","volume-title":"AutoZOOM: Autoencoder-based Zeroth Order Optimization Method for Attacking Black-box Neural Networks. arXiv preprint arXiv:1805.11770","author":"Tu Chun-Chen","year":"2018"},{"key":"e_1_3_2_1_32_1","volume-title":"The Limitations of Adversarial Training and the Blind-Spot Attack. International Conference on Learning Representations (ICLR)","author":"Zhang Huan","year":"2019"}],"event":{"name":"GECCO '19: Genetic and Evolutionary Computation Conference","location":"Prague Czech Republic","acronym":"GECCO '19","sponsor":["SIGEVO ACM Special Interest Group on Genetic and Evolutionary Computation"]},"container-title":["Proceedings of the Genetic and Evolutionary Computation Conference"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3321707.3321749","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3321707.3321749","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3321707.3321749","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T23:53:19Z","timestamp":1750204399000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3321707.3321749"}},"subtitle":["practical black-box attacks with gradient-free optimization"],"short-title":[],"issued":{"date-parts":[[2019,7,13]]},"references-count":32,"alternative-id":["10.1145\/3321707.3321749","10.1145\/3321707"],"URL":"https:\/\/doi.org\/10.1145\/3321707.3321749","relation":{},"subject":[],"published":{"date-parts":[[2019,7,13]]},"assertion":[{"value":"2019-07-13","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}