{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,31]],"date-time":"2026-07-31T15:44:30Z","timestamp":1785512670011,"version":"3.56.0"},"publisher-location":"New York, NY, USA","reference-count":35,"publisher":"ACM","license":[{"start":{"date-parts":[[2021,8,14]],"date-time":"2021-08-14T00:00:00Z","timestamp":1628899200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2021,8,14]]},"DOI":"10.1145\/3447548.3467386","type":"proceedings-article","created":{"date-parts":[[2021,8,13]],"date-time":"2021-08-13T18:33:08Z","timestamp":1628879588000},"page":"1461-1469","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":22,"title":["Simple and Efficient Hard Label Black-box Adversarial Attacks in Low Query Budget Regimes"],"prefix":"10.1145","author":[{"given":"Satya Narayan","family":"Shukla","sequence":"first","affiliation":[{"name":"University of Massachusetts Amherst, Amherst, MA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Anit Kumar","family":"Sahu","sequence":"additional","affiliation":[{"name":"Amazon Alexa AI, Seattle, WA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Devin","family":"Willmott","sequence":"additional","affiliation":[{"name":"Bosch Center for Artificial Intelligence, Pittsburgh, PA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zico","family":"Kolter","sequence":"additional","affiliation":[{"name":"Carnegie Mellon University, Pittsburgh, PA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2021,8,14]]},"reference":[{"key":"e_1_3_2_2_1_1","volume-title":"Decision-based adversarial attacks: Reliable attacks against black-box machine learning models. arXiv preprint arXiv:1712.04248","author":"Brendel Wieland","year":"2017","unstructured":"Wieland Brendel , Jonas Rauber , and Matthias Bethge . 2017. Decision-based adversarial attacks: Reliable attacks against black-box machine learning models. arXiv preprint arXiv:1712.04248 ( 2017 ). Wieland Brendel, Jonas Rauber, and Matthias Bethge. 2017. Decision-based adversarial attacks: Reliable attacks against black-box machine learning models. arXiv preprint arXiv:1712.04248 (2017)."},{"key":"e_1_3_2_2_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00506"},{"key":"e_1_3_2_2_3_1","volume-title":"Towards Evaluating the Robustness of Neural Networks. In 2017 IEEE Symposium on Security and Privacy (SP). 39--57","author":"Carlini N.","unstructured":"N. Carlini and D. Wagner . 2017 . Towards Evaluating the Robustness of Neural Networks. In 2017 IEEE Symposium on Security and Privacy (SP). 39--57 . N. Carlini and D. Wagner. 2017. Towards Evaluating the Robustness of Neural Networks. In 2017 IEEE Symposium on Security and Privacy (SP). 39--57."},{"key":"e_1_3_2_2_4_1","volume-title":"RayS: A Ray Searching Method for Hard-Label Adversarial Attack","author":"Chen Jinghui","unstructured":"Jinghui Chen and Quanquan Gu. 2020. RayS: A Ray Searching Method for Hard-Label Adversarial Attack . Association for Computing Machinery , 1739--1747. Jinghui Chen and Quanquan Gu. 2020. RayS: A Ray Searching Method for Hard-Label Adversarial Attack. Association for Computing Machinery, 1739--1747."},{"key":"e_1_3_2_2_5_1","volume-title":"Wainwright","author":"Chen Jianbo","year":"2019","unstructured":"Jianbo Chen , Michael I. Jordan , and Martin J . Wainwright . 2019 . HopSkipJumpAttack: A Query-Efficient Decision-Based Attack. ArXiv abs\/1904.02144 (2019). Jianbo Chen, Michael I. Jordan, and Martin J. Wainwright. 2019. HopSkipJumpAttack: A Query-Efficient Decision-Based Attack. ArXiv abs\/1904.02144 (2019)."},{"key":"e_1_3_2_2_6_1","volume-title":"A Frank-Wolfe Framework for Efficient and Effective Adversarial Attacks. ArXiv","author":"Chen Jinghui","year":"2018","unstructured":"Jinghui Chen , Jinfeng Yi , and Quanquan Gu. 2018. A Frank-Wolfe Framework for Efficient and Effective Adversarial Attacks. ArXiv , Vol. abs\/ 1811 .10828 ( 2018 ). Jinghui Chen, Jinfeng Yi, and Quanquan Gu. 2018. A Frank-Wolfe Framework for Efficient and Effective Adversarial Attacks. ArXiv, Vol. abs\/1811.10828 (2018)."},{"key":"e_1_3_2_2_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140448"},{"key":"e_1_3_2_2_8_1","volume-title":"Query-efficient hard-label black-box attack: An optimization-based approach. arXiv preprint arXiv:1807.04457","author":"Cheng Minhao","year":"2018","unstructured":"Minhao Cheng , Thong Le , Pin-Yu Chen , Jinfeng Yi , Huan Zhang , and Cho-Jui Hsieh . 2018. Query-efficient hard-label black-box attack: An optimization-based approach. arXiv preprint arXiv:1807.04457 ( 2018 ). Minhao Cheng, Thong Le, Pin-Yu Chen, Jinfeng Yi, Huan Zhang, and Cho-Jui Hsieh. 2018. Query-efficient hard-label black-box attack: An optimization-based approach. arXiv preprint arXiv:1807.04457 (2018)."},{"key":"e_1_3_2_2_9_1","volume-title":"Sign-OPT: A Query-Efficient Hard-label Adversarial Attack. In International Conference on Learning Representations.","author":"Cheng Minhao","year":"2020","unstructured":"Minhao Cheng , Simranjit Singh , Patrick H. Chen , Pin-Yu Chen , Sijia Liu , and Cho-Jui Hsieh . 2020 . Sign-OPT: A Query-Efficient Hard-label Adversarial Attack. In International Conference on Learning Representations. Minhao Cheng, Simranjit Singh, Patrick H. Chen, Pin-Yu Chen, Sijia Liu, and Cho-Jui Hsieh. 2020. Sign-OPT: A Query-Efficient Hard-label Adversarial Attack. In International Conference on Learning Representations."},{"key":"e_1_3_2_2_11_1","volume-title":"Luis Mu noz-Gonz\u00e1lez, and Emil C Lupu","author":"Co Kenneth T","year":"2018","unstructured":"Kenneth T Co , Luis Mu noz-Gonz\u00e1lez, and Emil C Lupu . 2018 . Procedural Noise Adversarial Examples for Black-Box Attacks on Deep Neural Networks . arXiv preprint arXiv:1810.00470 (2018). Kenneth T Co, Luis Mu noz-Gonz\u00e1lez, and Emil C Lupu. 2018. Procedural Noise Adversarial Examples for Black-Box Attacks on Deep Neural Networks. arXiv preprint arXiv:1810.00470 (2018)."},{"key":"e_1_3_2_2_12_1","doi-asserted-by":"crossref","unstructured":"J. Deng W. Dong R. Socher L.-J. Li K. Li and L. Fei-Fei. 2009. ImageNet: A Large-Scale Hierarchical Image Database. In CVPR09.  J. Deng W. Dong R. Socher L.-J. Li K. Li and L. Fei-Fei. 2009. ImageNet: A Large-Scale Hierarchical Image Database. In CVPR09.","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"e_1_3_2_2_13_1","volume-title":"A Tutorial on Bayesian Optimization. ArXiv","author":"Frazier Peter I.","year":"2018","unstructured":"Peter I. Frazier . 2018. A Tutorial on Bayesian Optimization. ArXiv , Vol. abs\/ 1807 .02811 ( 2018 ). Peter I. Frazier. 2018. A Tutorial on Bayesian Optimization. ArXiv, Vol. abs\/1807.02811 (2018)."},{"key":"e_1_3_2_2_14_1","volume-title":"Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572","author":"Goodfellow Ian J","year":"2014","unstructured":"Ian J Goodfellow , Jonathon Shlens , and Christian Szegedy . 2014. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 ( 2014 ). Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy. 2014. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 (2014)."},{"key":"e_1_3_2_2_15_1","volume-title":"Algorithmic Assurance: An Active Approach to Algorithmic Testing using Bayesian Optimisation. In Advances in Neural Information Processing Systems 31. 5465--5473.","author":"Gopakumar Shivapratap","year":"2018","unstructured":"Shivapratap Gopakumar , Sunil Gupta , Santu Rana , Vu Nguyen , and Svetha Venkatesh . 2018 . Algorithmic Assurance: An Active Approach to Algorithmic Testing using Bayesian Optimisation. In Advances in Neural Information Processing Systems 31. 5465--5473. Shivapratap Gopakumar, Sunil Gupta, Santu Rana, Vu Nguyen, and Svetha Venkatesh. 2018. Algorithmic Assurance: An Active Approach to Algorithmic Testing using Bayesian Optimisation. In Advances in Neural Information Processing Systems 31. 5465--5473."},{"key":"e_1_3_2_2_16_1","volume-title":"Weinberger","author":"Guo Chuan","year":"2018","unstructured":"Chuan Guo , Jared S. Frank , and Kilian Q . Weinberger . 2018 . Low Frequency Adversarial Perturbation. In UAI. Chuan Guo, Jared S. Frank, and Kilian Q. Weinberger. 2018. Low Frequency Adversarial Perturbation. In UAI."},{"key":"e_1_3_2_2_17_1","volume-title":"Andrew Gordon Wilson, and Kilian Q Weinberger","author":"Guo Chuan","year":"2019","unstructured":"Chuan Guo , Jacob R Gardner , Yurong You , Andrew Gordon Wilson, and Kilian Q Weinberger . 2019 . Simple black-box adversarial attacks. arXiv preprint arXiv:1905.07121 (2019). Chuan Guo, Jacob R Gardner, Yurong You, Andrew Gordon Wilson, and Kilian Q Weinberger. 2019. Simple black-box adversarial attacks. arXiv preprint arXiv:1905.07121 (2019)."},{"key":"e_1_3_2_2_18_1","volume-title":"Deep Residual Learning for Image Recognition. 2016 IEEE Conference on Computer Vision and Pattern Recognition (CVPR)","author":"He Kaiming","year":"2015","unstructured":"Kaiming He , Xiangyu Zhang , Shaoqing Ren , and Jian Sun . 2015 . Deep Residual Learning for Image Recognition. 2016 IEEE Conference on Computer Vision and Pattern Recognition (CVPR) (2015), 770--778. Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun. 2015. Deep Residual Learning for Image Recognition. 2016 IEEE Conference on Computer Vision and Pattern Recognition (CVPR) (2015), 770--778."},{"key":"e_1_3_2_2_19_1","volume-title":"Proceedings of the 35th International Conference on Machine Learning. 2137--2146","author":"Ilyas Andrew","year":"2018","unstructured":"Andrew Ilyas , Logan Engstrom , Anish Athalye , and Jessy Lin . 2018 . Black-box Adversarial Attacks with Limited Queries and Information . In Proceedings of the 35th International Conference on Machine Learning. 2137--2146 . Andrew Ilyas, Logan Engstrom, Anish Athalye, and Jessy Lin. 2018. Black-box Adversarial Attacks with Limited Queries and Information. In Proceedings of the 35th International Conference on Machine Learning. 2137--2146."},{"key":"e_1_3_2_2_20_1","volume-title":"Prior Convictions: Black-box Adversarial Attacks with Bandits and Priors. In International Conference on Learning Representations.","author":"Ilyas Andrew","year":"2019","unstructured":"Andrew Ilyas , Logan Engstrom , and Aleksander Madry . 2019 . Prior Convictions: Black-box Adversarial Attacks with Bandits and Priors. In International Conference on Learning Representations. Andrew Ilyas, Logan Engstrom, and Aleksander Madry. 2019. Prior Convictions: Black-box Adversarial Attacks with Bandits and Priors. In International Conference on Learning Representations."},{"key":"e_1_3_2_2_21_1","doi-asserted-by":"publisher","DOI":"10.1023\/A:1008306431147"},{"key":"e_1_3_2_2_22_1","unstructured":"Alex Krizhevsky Vinod Nair and Geoffrey Hinton. [n.d.]. CIFAR-10 (Canadian Institute for Advanced Research). ( [n. d.]).  Alex Krizhevsky Vinod Nair and Geoffrey Hinton. [n.d.]. CIFAR-10 (Canadian Institute for Advanced Research). ( [n. d.])."},{"key":"e_1_3_2_2_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"e_1_3_2_2_24_1","volume-title":"Delving into transferable adversarial examples and black-box attacks. ArXiv abs\/1611.02770","author":"Liu Yanpei","year":"2016","unstructured":"Yanpei Liu , Xinyun Chen , Chang Liu , and Dawn Song . 2016. Delving into transferable adversarial examples and black-box attacks. ArXiv abs\/1611.02770 ( 2016 ). Yanpei Liu, Xinyun Chen, Chang Liu, and Dawn Song. 2016. Delving into transferable adversarial examples and black-box attacks. ArXiv abs\/1611.02770 (2016)."},{"key":"e_1_3_2_2_25_1","volume-title":"Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083","author":"Madry Aleksander","year":"2017","unstructured":"Aleksander Madry , Aleksandar Makelov , Ludwig Schmidt , Dimitris Tsipras , and Adrian Vladu . 2017. Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083 ( 2017 ). Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2017. Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083 (2017)."},{"key":"e_1_3_2_2_26_1","volume-title":"Proceedings of the 36th International Conference on Machine Learning. 4636--4645","author":"Moon Seungyong","year":"2019","unstructured":"Seungyong Moon , Gaon An , and Hyun Oh Song . 2019 . Parsimonious Black-Box Adversarial Attacks via Efficient Combinatorial Optimization . In Proceedings of the 36th International Conference on Machine Learning. 4636--4645 . Seungyong Moon, Gaon An, and Hyun Oh Song. 2019. Parsimonious Black-Box Adversarial Attacks via Efficient Combinatorial Optimization. In Proceedings of the 36th International Conference on Machine Learning. 4636--4645."},{"key":"e_1_3_2_2_27_1","volume-title":"Practical Black-Box Attacks against Machine Learning. CoRR","author":"Papernot Nicolas","year":"2016","unstructured":"Nicolas Papernot , Patrick D. McDaniel , Ian J. Goodfellow , Somesh Jha , Z. Berkay Celik , and Ananthram Swami . 2016. Practical Black-Box Attacks against Machine Learning. CoRR , Vol. abs\/ 1602 .02697 ( 2016 ). arxiv: 1602.02697 Nicolas Papernot, Patrick D. McDaniel, Ian J. Goodfellow, Somesh Jha, Z. Berkay Celik, and Ananthram Swami. 2016. Practical Black-Box Attacks against Machine Learning. CoRR, Vol. abs\/1602.02697 (2016). arxiv: 1602.02697"},{"key":"e_1_3_2_2_28_1","volume-title":"Williams","author":"Rasmussen Carl Edward","year":"2006","unstructured":"Carl Edward Rasmussen and Christopher K. I . Williams . 2006 . Gaussian processes for machine learning. Carl Edward Rasmussen and Christopher K. I. Williams. 2006. Gaussian processes for machine learning."},{"key":"e_1_3_2_2_29_1","volume-title":"BayesOpt Adversarial Attack. In International Conference on Learning Representations.","author":"Ru Binxin","year":"2020","unstructured":"Binxin Ru , Adam Cobb , Arno Blaas , and Yarin Gal . 2020 . BayesOpt Adversarial Attack. In International Conference on Learning Representations. Binxin Ru, Adam Cobb, Arno Blaas, and Yarin Gal. 2020. BayesOpt Adversarial Attack. In International Conference on Learning Representations."},{"key":"e_1_3_2_2_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/JPROC.2015.2494218"},{"key":"e_1_3_2_2_31_1","unstructured":"Karen Simonyan and Andrew Zisserman. 2014. Very Deep Convolutional Networks for Large-Scale Image Recognition. cite arxiv:1409.1556.  Karen Simonyan and Andrew Zisserman. 2014. Very Deep Convolutional Networks for Large-Scale Image Recognition. cite arxiv:1409.1556."},{"key":"e_1_3_2_2_32_1","unstructured":"Jasper Snoek Hugo Larochelle and Ryan P Adams. 2012. Practical Bayesian Optimization of Machine Learning Algorithms. In Advances in Neural Information Processing Systems. 2951--2959.  Jasper Snoek Hugo Larochelle and Ryan P Adams. 2012. Practical Bayesian Optimization of Machine Learning Algorithms. In Advances in Neural Information Processing Systems. 2951--2959."},{"key":"e_1_3_2_2_33_1","volume-title":"Query-limited black-box attacks to classifiers. arXiv preprint arXiv:1712.08713","author":"Suya Fnu","year":"2017","unstructured":"Fnu Suya , Yuan Tian , David Evans , and Paolo Papotti . 2017. Query-limited black-box attacks to classifiers. arXiv preprint arXiv:1712.08713 ( 2017 ). Fnu Suya, Yuan Tian, David Evans, and Paolo Papotti. 2017. Query-limited black-box attacks to classifiers. arXiv preprint arXiv:1712.08713 (2017)."},{"key":"e_1_3_2_2_34_1","volume-title":"Rethinking the Inception Architecture for Computer Vision. IEEE Conference on Computer Vision and Pattern Recognition","author":"Szegedy Christian","year":"2016","unstructured":"Christian Szegedy , Vincent Vanhoucke , Sergey Ioffe , Jonathon Shlens , and Zbigniew Wojna . 2016 . Rethinking the Inception Architecture for Computer Vision. IEEE Conference on Computer Vision and Pattern Recognition (2016). Christian Szegedy, Vincent Vanhoucke, Sergey Ioffe, Jonathon Shlens, and Zbigniew Wojna. 2016. Rethinking the Inception Architecture for Computer Vision. IEEE Conference on Computer Vision and Pattern Recognition (2016)."},{"key":"e_1_3_2_2_35_1","doi-asserted-by":"crossref","unstructured":"Chun-Chen Tu Pai-Shun Ting Pin-Yu Chen Sijia Liu Huan Zhang Jinfeng Yi Cho-Jui Hsieh and Shin-Ming Cheng. 2019. AutoZOOM: Autoencoder-Based Zeroth Order Optimization Method for Attacking Black-Box Neural Networks. In AAAI. 742--749.  Chun-Chen Tu Pai-Shun Ting Pin-Yu Chen Sijia Liu Huan Zhang Jinfeng Yi Cho-Jui Hsieh and Shin-Ming Cheng. 2019. AutoZOOM: Autoencoder-Based Zeroth Order Optimization Method for Attacking Black-Box Neural Networks. In AAAI. 742--749.","DOI":"10.1609\/aaai.v33i01.3301742"},{"key":"e_1_3_2_2_36_1","volume-title":"Kaidi Xu, Bhavya Kailkhura, and X Cai Lin.","author":"Zhao Pu","year":"2019","unstructured":"Pu Zhao , Sijia Liu , Pin-Yu Chen , Nghia Nguy\u00ean Ho\u00e0ng , Kaidi Xu, Bhavya Kailkhura, and X Cai Lin. 2019 . On the Design of Black-box Adversarial Examples by Leveraging Gradient-free Optimization and Operator Splitting Method. ArXiv , Vol. abs\/ 1907 .11684 (2019). Pu Zhao, Sijia Liu, Pin-Yu Chen, Nghia Nguy\u00ean Ho\u00e0ng, Kaidi Xu, Bhavya Kailkhura, and X Cai Lin. 2019. On the Design of Black-box Adversarial Examples by Leveraging Gradient-free Optimization and Operator Splitting Method. ArXiv, Vol. abs\/1907.11684 (2019)."}],"event":{"name":"KDD '21: The 27th ACM SIGKDD Conference on Knowledge Discovery and Data Mining","location":"Virtual Event Singapore","acronym":"KDD '21","sponsor":["SIGMOD ACM Special Interest Group on Management of Data","SIGKDD ACM Special Interest Group on Knowledge Discovery in Data"]},"container-title":["Proceedings of the 27th ACM SIGKDD Conference on Knowledge Discovery &amp; Data Mining"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3447548.3467386","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3447548.3467386","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T20:18:23Z","timestamp":1750191503000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3447548.3467386"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,8,14]]},"references-count":35,"alternative-id":["10.1145\/3447548.3467386","10.1145\/3447548"],"URL":"https:\/\/doi.org\/10.1145\/3447548.3467386","relation":{},"subject":[],"published":{"date-parts":[[2021,8,14]]},"assertion":[{"value":"2021-08-14","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}