{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,11]],"date-time":"2025-12-11T20:59:17Z","timestamp":1765486757812,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":32,"publisher":"ACM","license":[{"start":{"date-parts":[[2022,4,18]],"date-time":"2022-04-18T00:00:00Z","timestamp":1650240000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2022,4,18]]},"DOI":"10.1145\/3510548.3519373","type":"proceedings-article","created":{"date-parts":[[2022,4,23]],"date-time":"2022-04-23T10:15:01Z","timestamp":1650708901000},"page":"13-23","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["Enhancing Boundary Attack in Adversarial Image Using Square Random Constraint"],"prefix":"10.1145","author":[{"given":"Tran Van","family":"Sang","sequence":"first","affiliation":[{"name":"The University of Tokyo, Tokyo, Japan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tran Phuong","family":"Thao","sequence":"additional","affiliation":[{"name":"The University of Tokyo, Tokyo, Japan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Rie","family":"Shigetomi Yamaguchi","sequence":"additional","affiliation":[{"name":"The University of Tokyo, Tokyo, Japan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Toshiyuki","family":"Nakata","sequence":"additional","affiliation":[{"name":"The University of Tokyo, Tokyo, Japan"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2022,4,23]]},"reference":[{"key":"e_1_3_2_2_1_1","unstructured":"2015. TensorFlow: Large-Scale Machine Learning on Heterogeneous Systems. http:\/\/tensorflow.org\/ Software available from tensorflow.org.  2015. TensorFlow: Large-Scale Machine Learning on Heterogeneous Systems. http:\/\/tensorflow.org\/ Software available from tensorflow.org."},{"key":"e_1_3_2_2_2_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58592-1_29"},{"key":"e_1_3_2_2_3_1","doi-asserted-by":"publisher","DOI":"10.23919\/CYCON.2018.8405026"},{"key":"e_1_3_2_2_4_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01258-8_10"},{"key":"e_1_3_2_2_5_1","volume-title":"Decision-Based Adversarial Attacks: Reliable Attacks Against Black-Box Machine Learning Models. In International Conference on Learning Representations (ICLR'18)","author":"Brendel Wieland","year":"2018","unstructured":"Wieland Brendel , Jonas Rauber , and Matthias Bethge . 2018 . Decision-Based Adversarial Attacks: Reliable Attacks Against Black-Box Machine Learning Models. In International Conference on Learning Representations (ICLR'18) . Wieland Brendel, Jonas Rauber, and Matthias Bethge. 2018. Decision-Based Adversarial Attacks: Reliable Attacks Against Black-Box Machine Learning Models. In International Conference on Learning Representations (ICLR'18)."},{"key":"e_1_3_2_2_6_1","volume-title":"Guessing Smart: Biased Sampling for Efficient Black-Box Adversarial Attacks. In 2019 IEEE\/CVF International Conference on Computer Vision (ICCV'19)","author":"Brunner Thomas","year":"2019","unstructured":"Thomas Brunner , Frederik Diehl , Michael Truong Le , and Alois Knoll . 2019 . Guessing Smart: Biased Sampling for Efficient Black-Box Adversarial Attacks. In 2019 IEEE\/CVF International Conference on Computer Vision (ICCV'19) . 4957--4965. https:\/\/doi.org\/10.1109\/ICCV.2019.00506 Thomas Brunner, Frederik Diehl, Michael Truong Le, and Alois Knoll. 2019. Guessing Smart: Biased Sampling for Efficient Black-Box Adversarial Attacks. In 2019 IEEE\/CVF International Conference on Computer Vision (ICCV'19). 4957--4965. https:\/\/doi.org\/10.1109\/ICCV.2019.00506"},{"key":"e_1_3_2_2_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"e_1_3_2_2_8_1","volume-title":"HopSkipJumpAttack: A Query-Efficient Decision-Based Attack. In 2020 IEEE Symposium on Security and Privacy (S&P). 1277--1294","author":"Chen Jianbo","year":"2020","unstructured":"Jianbo Chen , Michael I. Jordan , and Martin J. Wainwright . 2020 . HopSkipJumpAttack: A Query-Efficient Decision-Based Attack. In 2020 IEEE Symposium on Security and Privacy (S&P). 1277--1294 . https:\/\/doi.org\/10.1109\/SP40000. 2020 .00045 Jianbo Chen, Michael I. Jordan, and Martin J. Wainwright. 2020. HopSkipJumpAttack: A Query-Efficient Decision-Based Attack. In 2020 IEEE Symposium on Security and Privacy (S&P). 1277--1294. https:\/\/doi.org\/10.1109\/SP40000.2020.00045"},{"key":"e_1_3_2_2_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140448"},{"key":"e_1_3_2_2_10_1","volume-title":"Query-Efficient Hard-label Black-box Attack: An Optimization-based Approach. In 7th International Conference on Learning Representations, ICLR 2019","author":"Cheng Minhao","year":"2019","unstructured":"Minhao Cheng , Thong Le , Pin-Yu Chen , Huan Zhang , Jinfeng Yi , and Cho-Jui Hsieh . 2019 . Query-Efficient Hard-label Black-box Attack: An Optimization-based Approach. In 7th International Conference on Learning Representations, ICLR 2019 , New Orleans, LA, USA, May 6--9 , 2019. OpenReview.net. https:\/\/openreview.net\/forum?id=rJlk6iRqKX Minhao Cheng, Thong Le, Pin-Yu Chen, Huan Zhang, Jinfeng Yi, and Cho-Jui Hsieh. 2019. Query-Efficient Hard-label Black-box Attack: An Optimization-based Approach. In 7th International Conference on Learning Representations, ICLR 2019, New Orleans, LA, USA, May 6--9, 2019. OpenReview.net. https:\/\/openreview.net\/forum?id=rJlk6iRqKX"},{"key":"e_1_3_2_2_11_1","unstructured":"Franccois Chollet et al. 2015. Keras. https:\/\/github.com\/fchollet\/keras.  Franccois Chollet et al. 2015. Keras. https:\/\/github.com\/fchollet\/keras."},{"key":"e_1_3_2_2_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/3270101.3270106"},{"key":"e_1_3_2_2_13_1","volume-title":"Explaining and Harnessing Adversarial Examples. In International Conference on Learning Representations (ICLR'15)","author":"Goodfellow Ian","year":"2015","unstructured":"Ian Goodfellow , Jonathon Shlens , and Christian Szegedy . 2015 . Explaining and Harnessing Adversarial Examples. In International Conference on Learning Representations (ICLR'15) . Ian Goodfellow, Jonathon Shlens, and Christian Szegedy. 2015. Explaining and Harnessing Adversarial Examples. In International Conference on Learning Representations (ICLR'15)."},{"key":"e_1_3_2_2_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243792"},{"key":"e_1_3_2_2_15_1","volume-title":"Learning Universal Adversarial Perturbations with Generative Models. In 2018 IEEE Security and Privacy Workshops (SPW). 43--49","author":"Hayes Jamie","year":"2018","unstructured":"Jamie Hayes and George Danezis . 2018 . Learning Universal Adversarial Perturbations with Generative Models. In 2018 IEEE Security and Privacy Workshops (SPW). 43--49 . https:\/\/doi.org\/10.1109\/SPW.2018.00015 Jamie Hayes and George Danezis. 2018. Learning Universal Adversarial Perturbations with Generative Models. In 2018 IEEE Security and Privacy Workshops (SPW). 43--49. https:\/\/doi.org\/10.1109\/SPW.2018.00015"},{"volume-title":"Computer Vision -- ECCV 2016 ,","author":"He Kaiming","key":"e_1_3_2_2_16_1","unstructured":"Kaiming He , Xiangyu Zhang , Shaoqing Ren , and Jian Sun . 2016. Identity Mappings in Deep Residual Networks . In Computer Vision -- ECCV 2016 , , Bastian Leibe, Jiri Matas, Nicu Sebe, and Max Welling (Eds.). Springer International Publishing , Cham , 630--645. Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun. 2016. Identity Mappings in Deep Residual Networks. In Computer Vision -- ECCV 2016 , , Bastian Leibe, Jiri Matas, Nicu Sebe, and Max Welling (Eds.). Springer International Publishing, Cham, 630--645."},{"key":"e_1_3_2_2_17_1","volume-title":"IEEE International Joint Conference on Neural Networks (IJCNN'21)","author":"Tran Phuong Thao","year":"2021","unstructured":"Phuong Thao Tran , Hidano Seria , Bracamonte Vanessa , Kiyomoto Shinsaku , and Shigetomi Yamaguchi Rie . 2021 . OPA2D: One-Pixel Attack, Detection, and Defense in Deep Neural Networks . In IEEE International Joint Conference on Neural Networks (IJCNN'21) . Phuong Thao Tran, Hidano Seria, Bracamonte Vanessa, Kiyomoto Shinsaku, and Shigetomi Yamaguchi Rie. 2021. OPA2D: One-Pixel Attack, Detection, and Defense in Deep Neural Networks. In IEEE International Joint Conference on Neural Networks (IJCNN'21)."},{"key":"e_1_3_2_2_18_1","volume-title":"Proceedings of the 35th International Conference on Machine Learning (ICML'18)","volume":"2146","author":"Ilyas Andrew","year":"2018","unstructured":"Andrew Ilyas , Logan Engstrom , Anish Athalye , and Jessy Lin . 2018 . Black-box Adversarial Attacks with Limited Queries and Information . In Proceedings of the 35th International Conference on Machine Learning (ICML'18) (Proceedings of Machine Learning Research , Vol. 80), Jennifer Dy and Andreas Krause (Eds.). PMLR, 2137-- 2146 . http:\/\/proceedings.mlr.press\/v80\/ilyas18a.html Andrew Ilyas, Logan Engstrom, Anish Athalye, and Jessy Lin. 2018. Black-box Adversarial Attacks with Limited Queries and Information. In Proceedings of the 35th International Conference on Machine Learning (ICML'18) (Proceedings of Machine Learning Research, Vol. 80), Jennifer Dy and Andreas Krause (Eds.). PMLR, 2137--2146. http:\/\/proceedings.mlr.press\/v80\/ilyas18a.html"},{"key":"e_1_3_2_2_19_1","unstructured":"Andrew Ilyas Logan Engstrom and Aleksander Madry. 2019. Prior convictions: Black-box adversarial attacks with bandits and priors. (2019).  Andrew Ilyas Logan Engstrom and Aleksander Madry. 2019. Prior convictions: Black-box adversarial attacks with bandits and priors. (2019)."},{"key":"e_1_3_2_2_20_1","unstructured":"Jianbo-Lab. 2019. HopSkipJumpAttack. https:\/\/github.com\/Jianbo-Lab\/HSJA\/tree\/daecd5c7055d5214b39c34a7a28a98acd3557fbc.  Jianbo-Lab. 2019. HopSkipJumpAttack. https:\/\/github.com\/Jianbo-Lab\/HSJA\/tree\/daecd5c7055d5214b39c34a7a28a98acd3557fbc."},{"key":"e_1_3_2_2_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/3477.764879"},{"key":"e_1_3_2_2_22_1","unstructured":"A. Krizhevsky and G. Hinton. 2009. Learning multiple layers of features from tiny images. Master's thesis Department of Computer Science University of Toronto (2009).  A. Krizhevsky and G. Hinton. 2009. Learning multiple layers of features from tiny images. Master's thesis Department of Computer Science University of Toronto (2009)."},{"key":"e_1_3_2_2_23_1","unstructured":"Alex Krizhevsky Vinod Nair and Geoffrey Hinton. [n. d.]. CIFAR-10 (Canadian Institute for Advanced Research). ( [n. d.]). http:\/\/www.cs.toronto.edu\/ kriz\/cifar.html  Alex Krizhevsky Vinod Nair and Geoffrey Hinton. [n. d.]. CIFAR-10 (Canadian Institute for Advanced Research). ( [n. d.]). http:\/\/www.cs.toronto.edu\/ kriz\/cifar.html"},{"key":"e_1_3_2_2_24_1","doi-asserted-by":"crossref","unstructured":"Alexey Kurakin Ian Goodfellow and Samy Bengio. 2017. Adversarial examples in the physical world. (2017).  Alexey Kurakin Ian Goodfellow and Samy Bengio. 2017. Adversarial examples in the physical world. (2017).","DOI":"10.1201\/9781351251389-8"},{"key":"e_1_3_2_2_25_1","unstructured":"Yanpei Liu Xinyun Chen Chang Liu and Dawn Song. 2017. Delving into transferable adversarial examples and black-box attacks. (2017).  Yanpei Liu Xinyun Chen Chang Liu and Dawn Song. 2017. Delving into transferable adversarial examples and black-box attacks. (2017)."},{"key":"e_1_3_2_2_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00499"},{"key":"e_1_3_2_2_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"e_1_3_2_2_28_1","volume-title":"Simple Black-Box Adversarial Attacks on Deep Neural Networks. In 2017 IEEE Conference on Computer Vision and Pattern Recognition Workshops (CVPRW'17)","author":"Narodytska Nina","year":"2017","unstructured":"Nina Narodytska and Shiva Kasiviswanathan . 2017 . Simple Black-Box Adversarial Attacks on Deep Neural Networks. In 2017 IEEE Conference on Computer Vision and Pattern Recognition Workshops (CVPRW'17) . 1310--1318. https:\/\/doi.org\/10.1109\/CVPRW.2017.172 Nina Narodytska and Shiva Kasiviswanathan. 2017. Simple Black-Box Adversarial Attacks on Deep Neural Networks. In 2017 IEEE Conference on Computer Vision and Pattern Recognition Workshops (CVPRW'17). 1310--1318. https:\/\/doi.org\/10.1109\/CVPRW.2017.172"},{"key":"e_1_3_2_2_29_1","volume-title":"Biologically inspired protection of deep networks from adversarial attacks. CoRR","author":"Nayebi Aran","year":"2017","unstructured":"Aran Nayebi and Surya Ganguli . 2017. Biologically inspired protection of deep networks from adversarial attacks. CoRR , Vol. abs\/ 1703 .09202 ( 2017 ). http:\/\/arxiv.org\/abs\/1703.09202 Aran Nayebi and Surya Ganguli. 2017. Biologically inspired protection of deep networks from adversarial attacks. CoRR , Vol. abs\/1703.09202 (2017). http:\/\/arxiv.org\/abs\/1703.09202"},{"key":"e_1_3_2_2_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"key":"e_1_3_2_2_31_1","doi-asserted-by":"publisher","DOI":"10.21105\/joss.02607"},{"key":"e_1_3_2_2_32_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.3301742"}],"event":{"name":"CODASPY '22: Twelveth ACM Conference on Data and Application Security and Privacy","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"],"location":"Baltimore MD USA","acronym":"CODASPY '22"},"container-title":["Proceedings of the 2022 ACM on International Workshop on Security and Privacy Analytics"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3510548.3519373","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3510548.3519373","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T20:12:19Z","timestamp":1750191139000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3510548.3519373"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,4,18]]},"references-count":32,"alternative-id":["10.1145\/3510548.3519373","10.1145\/3510548"],"URL":"https:\/\/doi.org\/10.1145\/3510548.3519373","relation":{},"subject":[],"published":{"date-parts":[[2022,4,18]]},"assertion":[{"value":"2022-04-23","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}