{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,25]],"date-time":"2026-07-25T15:58:32Z","timestamp":1784995112552,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":31,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,8,4]],"date-time":"2023-08-04T00:00:00Z","timestamp":1691107200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,8,6]]},"DOI":"10.1145\/3580305.3599461","type":"proceedings-article","created":{"date-parts":[[2023,8,4]],"date-time":"2023-08-04T18:10:58Z","timestamp":1691172658000},"page":"3093-3104","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":10,"title":["PAT: Geometry-Aware Hard-Label Black-Box Adversarial Attacks on Text"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0006-9112-8895","authenticated-orcid":false,"given":"Muchao","family":"Ye","sequence":"first","affiliation":[{"name":"The Pennsylvania State University, University Park, PA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1486-4526","authenticated-orcid":false,"given":"Jinghui","family":"Chen","sequence":"additional","affiliation":[{"name":"The Pennsylvania State University, University Park, PA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9646-7099","authenticated-orcid":false,"given":"Chenglin","family":"Miao","sequence":"additional","affiliation":[{"name":"Iowa State University, Ames, IA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6921-2050","authenticated-orcid":false,"given":"Han","family":"Liu","sequence":"additional","affiliation":[{"name":"Dalian University of Technology, Dalian, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4927-5833","authenticated-orcid":false,"given":"Ting","family":"Wang","sequence":"additional","affiliation":[{"name":"The Pennsylvania State University, University Park, PA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4999-0303","authenticated-orcid":false,"given":"Fenglong","family":"Ma","sequence":"additional","affiliation":[{"name":"The Pennsylvania State University, University Park, PA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2023,8,4]]},"reference":[{"key":"e_1_3_2_2_1_1","unstructured":"Wieland Brendel Jonas Rauber and Matthias Bethge. 2018. Decision-Based Adversarial Attacks: Reliable Attacks Against Black-Box Machine Learning Models. In ICLR. OpenReview.net.  Wieland Brendel Jonas Rauber and Matthias Bethge. 2018. Decision-Based Adversarial Attacks: Reliable Attacks Against Black-Box Machine Learning Models. In ICLR. OpenReview.net."},{"key":"e_1_3_2_2_2_1","volume-title":"Wagner","author":"Carlini Nicholas","year":"2017","unstructured":"Nicholas Carlini and David A . Wagner . 2017 . Towards Evaluating the Robustness of Neural Networks. In S&P. IEEE Computer Society , 39--57. https:\/\/doi.org\/10.1109\/SP.2017.49 10.1109\/SP.2017.49 Nicholas Carlini and David A. Wagner. 2017. Towards Evaluating the Robustness of Neural Networks. In S&P. IEEE Computer Society, 39--57. https:\/\/doi.org\/10.1109\/SP.2017.49"},{"key":"e_1_3_2_2_3_1","volume-title":"Noah Constant, Mario Guajardo-C\u00e9spedes, Steve Yuan, Chris Tar, et al.","author":"Cer Daniel","year":"2018","unstructured":"Daniel Cer , Yinfei Yang , Sheng-yi Kong, Nan Hua , Nicole Limtiaco , Rhomni St John , Noah Constant, Mario Guajardo-C\u00e9spedes, Steve Yuan, Chris Tar, et al. 2018 . Universal sentence encoder. arXiv preprint arXiv:1803.11175 (2018). Daniel Cer, Yinfei Yang, Sheng-yi Kong, Nan Hua, Nicole Limtiaco, Rhomni St John, Noah Constant, Mario Guajardo-C\u00e9spedes, Steve Yuan, Chris Tar, et al. 2018. Universal sentence encoder. arXiv preprint arXiv:1803.11175 (2018)."},{"key":"e_1_3_2_2_4_1","volume-title":"Wainwright","author":"Chen Jianbo","year":"2020","unstructured":"Jianbo Chen , Michael I. Jordan , and Martin J . Wainwright . 2020 . HopSkipJumpAttack: A Query-Efficient Decision-Based Attack. In S&P. IEEE , 1277--1294. https:\/\/doi.org\/10.1109\/SP40000.2020.00045 10.1109\/SP40000.2020.00045 Jianbo Chen, Michael I. Jordan, and Martin J. Wainwright. 2020. HopSkipJumpAttack: A Query-Efficient Decision-Based Attack. In S&P. IEEE, 1277--1294. https:\/\/doi.org\/10.1109\/SP40000.2020.00045"},{"key":"e_1_3_2_2_5_1","unstructured":"Minhao Cheng Thong Le Pin-Yu Chen Huan Zhang Jinfeng Yi and Cho-Jui Hsieh. 2019. Query-Efficient Hard-label Black-box Attack: An Optimization-based Approach. In ICLR. OpenReview.net.  Minhao Cheng Thong Le Pin-Yu Chen Huan Zhang Jinfeng Yi and Cho-Jui Hsieh. 2019. Query-Efficient Hard-label Black-box Attack: An Optimization-based Approach. In ICLR. OpenReview.net."},{"key":"e_1_3_2_2_6_1","volume-title":"Sign-OPT: A Query-Efficient Hard-label Adversarial Attack. In International Conference on Learning Representations.","author":"Cheng Minhao","year":"2020","unstructured":"Minhao Cheng , Simranjit Singh , Patrick H. Chen , Pin-Yu Chen , Sijia Liu , and Cho-Jui Hsieh . 2020 . Sign-OPT: A Query-Efficient Hard-label Adversarial Attack. In International Conference on Learning Representations. Minhao Cheng, Simranjit Singh, Patrick H. Chen, Pin-Yu Chen, Sijia Liu, and Cho-Jui Hsieh. 2020. Sign-OPT: A Query-Efficient Hard-label Adversarial Attack. In International Conference on Learning Representations."},{"key":"e_1_3_2_2_7_1","volume-title":"BERT: Pre-training of Deep Bidirectional Transformers for Language Understanding","author":"Devlin Jacob","year":"2019","unstructured":"Jacob Devlin , Ming-Wei Chang , Kenton Lee , and Kristina Toutanova . 2019 . BERT: Pre-training of Deep Bidirectional Transformers for Language Understanding . In NAACL-HLT. Association for Computational Linguistics , 4171--4186. https:\/\/doi.org\/10.18653\/v1\/n19--1423 10.18653\/v1 Jacob Devlin, Ming-Wei Chang, Kenton Lee, and Kristina Toutanova. 2019. BERT: Pre-training of Deep Bidirectional Transformers for Language Understanding. In NAACL-HLT. Association for Computational Linguistics, 4171--4186. https:\/\/doi.org\/10.18653\/v1\/n19--1423"},{"key":"e_1_3_2_2_8_1","volume-title":"HotFlip: White-Box Adversarial Examples for Text Classification","author":"Ebrahimi Javid","year":"1865","unstructured":"Javid Ebrahimi , Anyi Rao , Daniel Lowd , and Dejing Dou . 2018. HotFlip: White-Box Adversarial Examples for Text Classification . In ACL. Association for Computational Linguistics , 31--36. https:\/\/doi.org\/10. 1865 3\/v1\/P18--2006 10.18653\/v1 Javid Ebrahimi, Anyi Rao, Daniel Lowd, and Dejing Dou. 2018. HotFlip: White-Box Adversarial Examples for Text Classification. In ACL. Association for Computational Linguistics, 31--36. https:\/\/doi.org\/10.18653\/v1\/P18--2006"},{"key":"e_1_3_2_2_9_1","unstructured":"Ian J. Goodfellow Jonathon Shlens and Christian Szegedy. 2015. Explaining and Harnessing Adversarial Examples. In ICLR.  Ian J. Goodfellow Jonathon Shlens and Christian Szegedy. 2015. Explaining and Harnessing Adversarial Examples. In ICLR."},{"key":"e_1_3_2_2_10_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.emnlp-main.464"},{"key":"e_1_3_2_2_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"e_1_3_2_2_12_1","doi-asserted-by":"publisher","DOI":"10.1162\/neco.1997.9.8.1735"},{"key":"e_1_3_2_2_13_1","volume-title":"Joey Tianyi Zhou, and Peter Szolovits","author":"Jin Di","year":"2020","unstructured":"Di Jin , Zhijing Jin , Joey Tianyi Zhou, and Peter Szolovits . 2020 . Is BERT Really Robust? A Strong Baseline for Natural Language Attack on Text Classification and Entailment. In AAAI. AAAI Press , 8018--8025. Di Jin, Zhijing Jin, Joey Tianyi Zhou, and Peter Szolovits. 2020. Is BERT Really Robust? A Strong Baseline for Natural Language Attack on Text Classification and Entailment. In AAAI. AAAI Press, 8018--8025."},{"key":"#cr-split#-e_1_3_2_2_14_1.1","unstructured":"Yoon Kim. 2014. Convolutional Neural Networks for Sentence Classification. In EMNLP. ACL 1746--1751. https:\/\/doi.org\/10.3115\/v1\/d14--1181 10.3115\/v1"},{"key":"#cr-split#-e_1_3_2_2_14_1.2","doi-asserted-by":"crossref","unstructured":"Yoon Kim. 2014. Convolutional Neural Networks for Sentence Classification. In EMNLP. ACL 1746--1751. https:\/\/doi.org\/10.3115\/v1\/d14--1181","DOI":"10.3115\/v1\/D14-1181"},{"key":"e_1_3_2_2_15_1","doi-asserted-by":"crossref","unstructured":"Alexey Kurakin Ian J. Goodfellow and Samy Bengio. 2017. Adversarial examples in the physical world. In ICLR. OpenReview.net.  Alexey Kurakin Ian J. Goodfellow and Samy Bengio. 2017. Adversarial examples in the physical world. In ICLR. OpenReview.net.","DOI":"10.1201\/9781351251389-8"},{"key":"e_1_3_2_2_16_1","unstructured":"Jinfeng Li Shouling Ji Tianyu Du Bo Li and Ting Wang. 2019. TextBugger: Generating Adversarial Text Against Real-world Applications. In NDSS.  Jinfeng Li Shouling Ji Tianyu Du Bo Li and Ting Wang. 2019. TextBugger: Generating Adversarial Text Against Real-world Applications. In NDSS."},{"key":"e_1_3_2_2_17_1","volume-title":"Learning Word Vectors for Sentiment Analysis","author":"Maas Andrew L.","unstructured":"Andrew L. Maas , Raymond E. Daly , Peter T. Pham , Dan Huang , Andrew Y. Ng , and Christopher Potts . 2011. Learning Word Vectors for Sentiment Analysis . In ACL. The Association for Computer Linguistics , 142--150. Andrew L. Maas, Raymond E. Daly, Peter T. Pham, Dan Huang, Andrew Y. Ng, and Christopher Potts. 2011. Learning Word Vectors for Sentiment Analysis. In ACL. The Association for Computer Linguistics, 142--150."},{"key":"e_1_3_2_2_18_1","volume-title":"6th International Conference on Learning Representations, ICLR","author":"Madry Aleksander","year":"2018","unstructured":"Aleksander Madry , Aleksandar Makelov , Ludwig Schmidt , Dimitris Tsipras , and Adrian Vladu . 2018. Towards Deep Learning Models Resistant to Adversarial Attacks . In 6th International Conference on Learning Representations, ICLR 2018 , Vancouver, BC , Canada, April 30 - May 3, 2018, Conference Track Proceedings. OpenReview .net. https:\/\/openreview.net\/forum?id=rJzIBfZAb Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2018. Towards Deep Learning Models Resistant to Adversarial Attacks. In 6th International Conference on Learning Representations, ICLR 2018, Vancouver, BC, Canada, April 30 - May 3, 2018, Conference Track Proceedings. OpenReview.net. https:\/\/openreview.net\/forum?id=rJzIBfZAb"},{"key":"e_1_3_2_2_19_1","doi-asserted-by":"crossref","unstructured":"Rishabh Maheshwary Saket Maheshwary and Vikram Pudi. 2021. Generating Natural Language Attacks in a Hard Label Black Box Setting. In AAAI.  Rishabh Maheshwary Saket Maheshwary and Vikram Pudi. 2021. Generating Natural Language Attacks in a Hard Label Black Box Setting. In AAAI.","DOI":"10.1609\/aaai.v35i15.17595"},{"key":"e_1_3_2_2_20_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/N19-1314"},{"key":"e_1_3_2_2_21_1","volume-title":"Blaise Thomson, Milica Gasic, Lina Maria Rojas-Barahona, Pei-Hao Su, David Vandyke, Tsung-Hsien Wen, and Steve J. Young.","author":"Mrksic Nikola","year":"2016","unstructured":"Nikola Mrksic , Diarmuid \u00d3 S\u00e9 aghdha , Blaise Thomson, Milica Gasic, Lina Maria Rojas-Barahona, Pei-Hao Su, David Vandyke, Tsung-Hsien Wen, and Steve J. Young. 2016 . Counter-fitting Word Vectors to Linguistic Constraints. In NAACL HLT 2016. The Association for Computational Linguistics , 142--148. Nikola Mrksic, Diarmuid \u00d3 S\u00e9 aghdha, Blaise Thomson, Milica Gasic, Lina Maria Rojas-Barahona, Pei-Hao Su, David Vandyke, Tsung-Hsien Wen, and Steve J. Young. 2016. Counter-fitting Word Vectors to Linguistic Constraints. In NAACL HLT 2016. The Association for Computational Linguistics, 142--148."},{"key":"e_1_3_2_2_22_1","volume-title":"Seeing Stars: Exploiting Class Relationships for Sentiment Categorization with Respect to Rating Scales","author":"Pang Bo","year":"2005","unstructured":"Bo Pang and Lillian Lee . 2005 . Seeing Stars: Exploiting Class Relationships for Sentiment Categorization with Respect to Rating Scales . In ACL. The Association for Computer Linguistics , 115--124. https:\/\/doi.org\/10.3115\/1219840.1219855 10.3115\/1219840.1219855 Bo Pang and Lillian Lee. 2005. Seeing Stars: Exploiting Class Relationships for Sentiment Categorization with Respect to Rating Scales. In ACL. The Association for Computer Linguistics, 115--124. https:\/\/doi.org\/10.3115\/1219840.1219855"},{"key":"e_1_3_2_2_23_1","volume-title":"Smoothed Embeddings for Certified Few-Shot Learning. Neurips","author":"Pautov Mikhail","year":"2022","unstructured":"Mikhail Pautov , Olesya Kuznetsova , Nurislam Tursynbek , Aleksandr Petiushko , and Ivan Oseledets . 2022. Smoothed Embeddings for Certified Few-Shot Learning. Neurips ( 2022 ). Mikhail Pautov, Olesya Kuznetsova, Nurislam Tursynbek, Aleksandr Petiushko, and Ivan Oseledets. 2022. Smoothed Embeddings for Certified Few-Shot Learning. Neurips (2022)."},{"key":"e_1_3_2_2_24_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.emnlp-main.374"},{"key":"e_1_3_2_2_25_1","volume-title":"Generating Natural Language Adversarial Examples through Probability Weighted Word Saliency","author":"Ren Shuhuai","year":"1865","unstructured":"Shuhuai Ren , Yihe Deng , Kun He , and Wanxiang Che . 2019. Generating Natural Language Adversarial Examples through Probability Weighted Word Saliency . In ACL. Association for Computational Linguistics , 1085--1097. https:\/\/doi.org\/10. 1865 3\/v1\/p19--1103 10.18653\/v1 Shuhuai Ren, Yihe Deng, Kun He, and Wanxiang Che. 2019. Generating Natural Language Adversarial Examples through Probability Weighted Word Saliency. In ACL. Association for Computational Linguistics, 1085--1097. https:\/\/doi.org\/10.18653\/v1\/p19--1103"},{"key":"e_1_3_2_2_26_1","volume-title":"Textdecepter: Hard label black box attack on text classifiers. arXiv preprint arXiv:2008.06860","author":"Saxena Sachin","year":"2020","unstructured":"Sachin Saxena . 2020 . Textdecepter: Hard label black box attack on text classifiers. arXiv preprint arXiv:2008.06860 (2020). Sachin Saxena. 2020. Textdecepter: Hard label black box attack on text classifiers. arXiv preprint arXiv:2008.06860 (2020)."},{"key":"e_1_3_2_2_27_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-46478-7_31"},{"key":"e_1_3_2_2_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/3534678.3539357"},{"key":"e_1_3_2_2_29_1","volume-title":"TextHoaxer: Budgeted Hard-Label Adversarial Attacks on Text. AAAI","author":"Ye Muchao","year":"2022","unstructured":"Muchao Ye , Chenglin Miao , Ting Wang , and Fenglong Ma. 2022b. TextHoaxer: Budgeted Hard-Label Adversarial Attacks on Text. AAAI ( 2022 ). Muchao Ye, Chenglin Miao, Ting Wang, and Fenglong Ma. 2022b. TextHoaxer: Budgeted Hard-Label Adversarial Attacks on Text. AAAI (2022)."},{"key":"e_1_3_2_2_30_1","volume-title":"Junbo Jake Zhao, and Yann LeCun","author":"Zhang Xiang","year":"2015","unstructured":"Xiang Zhang , Junbo Jake Zhao, and Yann LeCun . 2015 . Character-level Convolutional Networks for Text Classification. In NeurIPS. 649--657. io Xiang Zhang, Junbo Jake Zhao, and Yann LeCun. 2015. Character-level Convolutional Networks for Text Classification. In NeurIPS. 649--657. io"}],"event":{"name":"KDD '23: The 29th ACM SIGKDD Conference on Knowledge Discovery and Data Mining","location":"Long Beach CA USA","acronym":"KDD '23","sponsor":["SIGMOD ACM Special Interest Group on Management of Data","SIGKDD ACM Special Interest Group on Knowledge Discovery in Data"]},"container-title":["Proceedings of the 29th ACM SIGKDD Conference on Knowledge Discovery and Data Mining"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3580305.3599461","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3580305.3599461","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T16:37:37Z","timestamp":1750178257000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3580305.3599461"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,8,4]]},"references-count":31,"alternative-id":["10.1145\/3580305.3599461","10.1145\/3580305"],"URL":"https:\/\/doi.org\/10.1145\/3580305.3599461","relation":{},"subject":[],"published":{"date-parts":[[2023,8,4]]},"assertion":[{"value":"2023-08-04","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}