{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,8]],"date-time":"2026-05-08T16:49:50Z","timestamp":1778258990738,"version":"3.51.4"},"publisher-location":"New York, NY, USA","reference-count":37,"publisher":"ACM","funder":[{"name":"SEU Innovation Capability Enhancement Plan for Doctoral Students","award":["CXJH_SEU 24237"],"award-info":[{"award-number":["CXJH_SEU 24237"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,8,3]]},"DOI":"10.1145\/3711896.3736946","type":"proceedings-article","created":{"date-parts":[[2025,8,1]],"date-time":"2025-08-01T13:30:13Z","timestamp":1754055013000},"page":"1083-1093","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["Experience Speaks Louder: Black-box Hard-label Adversarial Attack through Reinforcement Learning"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-4620-9411","authenticated-orcid":false,"given":"Yilun","family":"Jin","sequence":"first","affiliation":[{"name":"School of Cyber Science and Engineering, Southeast University, Nanjing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7374-8015","authenticated-orcid":false,"given":"Kun","family":"Zhu","sequence":"additional","affiliation":[{"name":"College of Control Science and Engineering, Zhejiang University, Hangzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-6059-6669","authenticated-orcid":false,"given":"Feng","family":"Tang","sequence":"additional","affiliation":[{"name":"School of Economics and Management, Southeast University, Nanjing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-0027-7226","authenticated-orcid":false,"given":"Jiaxuan","family":"Shi","sequence":"additional","affiliation":[{"name":"Shanghai Research Institute for Intelligent Autonomous Systems, Tongji University, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3953-8313","authenticated-orcid":false,"given":"Yong","family":"Chen","sequence":"additional","affiliation":[{"name":"School of Information Technology and Artificial Intelligence, Zhejiang University of Finance and Economics, Hangzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2025,8,3]]},"reference":[{"key":"e_1_3_2_2_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/3655103.3655106"},{"key":"e_1_3_2_2_2_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D18-2029"},{"key":"e_1_3_2_2_3_1","volume-title":"Bert: Pre-training of deep bidirectional transformers for language understanding. arXiv preprint arXiv:1810.04805","author":"Devlin Jacob","year":"2018","unstructured":"Jacob Devlin. 2018. Bert: Pre-training of deep bidirectional transformers for language understanding. arXiv preprint arXiv:1810.04805 (2018)."},{"key":"e_1_3_2_2_4_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103378"},{"key":"e_1_3_2_2_5_1","volume-title":"Hotflip: Whitebox adversarial examples for text classification. arXiv preprint arXiv:1712.06751","author":"Ebrahimi Javid","year":"2017","unstructured":"Javid Ebrahimi, Anyi Rao, Daniel Lowd, and Dejing Dou. 2017. Hotflip: Whitebox adversarial examples for text classification. arXiv preprint arXiv:1712.06751 (2017)."},{"key":"e_1_3_2_2_6_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/P18-2006"},{"key":"e_1_3_2_2_7_1","volume-title":"Bae: Bert-based adversarial examples for text classification. arXiv preprint arXiv:2004.01970","author":"Garg Siddhant","year":"2020","unstructured":"Siddhant Garg and Goutham Ramakrishnan. 2020. Bae: Bert-based adversarial examples for text classification. arXiv preprint arXiv:2004.01970 (2020)."},{"key":"e_1_3_2_2_8_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-24797-2"},{"key":"e_1_3_2_2_9_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10462-022-10195-4"},{"key":"e_1_3_2_2_10_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i05.6311"},{"key":"e_1_3_2_2_11_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2024.124002"},{"key":"e_1_3_2_2_12_1","volume-title":"Convolutional neural networks for sentence classification. arXiv preprint arXiv:2101.07597","author":"Kim Yoon","year":"2014","unstructured":"Yoon Kim. 2014. Convolutional neural networks for sentence classification. arXiv preprint arXiv:2101.07597 (2014), 1-9."},{"key":"e_1_3_2_2_13_1","volume-title":"Proceddings of the 8th International Conference on Learning Representations. Virtual.","author":"Krishna Kalpesh","year":"2020","unstructured":"Kalpesh Krishna, Gaurav Singh Tomar, Ankur P Parikh, Nicolas Papernot, and Mohit Iyyer. 2020. Thieves on sesame street! Model extraction of BERT-based APIs. In Proceddings of the 8th International Conference on Learning Representations. Virtual."},{"key":"e_1_3_2_2_14_1","first-page":"1207","volume-title":"Proceedings of the 17th International Conference on Machine Learning (ICML","author":"Langley P.","year":"2000","unstructured":"P. Langley. 2000. Crafting Papers on Machine Learning. In Proceedings of the 17th International Conference on Machine Learning (ICML 2000), Pat Langley (Ed.). Morgan Kaufmann, Stanford, CA, 1207-1216."},{"key":"e_1_3_2_2_15_1","first-page":"12478","volume-title":"Proceedings of the 19th International Conference on Machine Learning. PMLR","author":"Lee Deokjae","year":"2022","unstructured":"Deokjae Lee, Seungyong Moon, Junhyeok Lee, and Hyun Oh Song. 2022. Queryefficient and scalable black-box adversarial attacks on discrete sequential data via bayesian optimization. In Proceedings of the 19th International Conference on Machine Learning. PMLR, Maryland, USA, 12478-12497."},{"key":"e_1_3_2_2_16_1","volume-title":"Textbugger: Generating adversarial text against real-world applications. arXiv preprint arXiv:1812.05271","author":"Li Jinfeng","year":"2018","unstructured":"Jinfeng Li, Shouling Ji, Tianyu Du, Bo Li, and Ting Wang. 2018. Textbugger: Generating adversarial text against real-world applications. arXiv preprint arXiv:1812.05271 (2018), 1-9."},{"key":"e_1_3_2_2_17_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v37i11.26553"},{"key":"e_1_3_2_2_18_1","first-page":"1","volume-title":"Proceedings of the 37th Advances in Neural Information Processing Systems","author":"Liu Han","year":"2024","unstructured":"Han Liu, Zhi Xu, Xiaotong Zhang, Feng Zhang, Fenglong Ma, Hongyang Chen, Hong Yu, and Xianchao Zhang. 2024. HQA-attack: toward high quality black-box hard-label adversarial attack on text. In Proceedings of the 37th Advances in Neural Information Processing Systems. New Orleans, USA, 1-8."},{"key":"e_1_3_2_2_19_1","doi-asserted-by":"publisher","DOI":"10.5555\/2002472.2002491"},{"key":"e_1_3_2_2_20_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i15.17595"},{"key":"e_1_3_2_2_21_1","volume-title":"A geometry-inspired attack for generating natural language adversarial examples. arXiv preprint arXiv:2010.01345","author":"Meng Zhao","year":"2020","unstructured":"Zhao Meng and Roger Wattenhofer. 2020. A geometry-inspired attack for generating natural language adversarial examples. arXiv preprint arXiv:2010.01345 (2020)."},{"key":"e_1_3_2_2_22_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.emnlp-demos.16"},{"key":"e_1_3_2_2_23_1","volume-title":"Seeing stars: Exploiting class relationships for sentiment categorization with respect to rating scales. arXiv preprint cs\/0506075","author":"Pang Bo","year":"2005","unstructured":"Bo Pang and Lillian Lee. 2005. Seeing stars: Exploiting class relationships for sentiment categorization with respect to rating scales. arXiv preprint cs\/0506075 (2005)."},{"key":"e_1_3_2_2_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2023.3339802"},{"key":"e_1_3_2_2_25_1","doi-asserted-by":"publisher","DOI":"10.3115\/v1\/D14-1162"},{"key":"e_1_3_2_2_26_1","first-page":"9","article-title":"Language models are unsupervised multitask learners","volume":"1","author":"Radford Alec","year":"2019","unstructured":"Alec Radford, JeffreyWu, Rewon Child, David Luan, Dario Amodei, Ilya Sutskever, et al. 2019. Language models are unsupervised multitask learners. OpenAI Blog 1, 8 (2019), 9.","journal-title":"OpenAI Blog"},{"key":"e_1_3_2_2_27_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/P19-1103"},{"key":"e_1_3_2_2_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCP63557.2024.10793051"},{"key":"e_1_3_2_2_29_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v30i1.10295"},{"key":"e_1_3_2_2_30_1","doi-asserted-by":"crossref","unstructured":"Pengyu Wang Linyang Li Ke Ren Botian Jiang Dong Zhang and Xipeng Qiu. 2023. SeqXGPT: Sentence-level AI-generated text detection.","DOI":"10.18653\/v1\/2023.emnlp-main.73"},{"key":"e_1_3_2_2_31_1","volume-title":"Proceedings of the 30th Advances in Neural Information Processing Systems","author":"Waswani A","year":"2017","unstructured":"A Waswani, N Shazeer, N Parmar, J Uszkoreit, L Jones, A Gomez, L Kaiser, and I Polosukhin. 2017. Attention is all you need. In Proceedings of the 30th Advances in Neural Information Processing Systems. Barcelona, Spain."},{"key":"e_1_3_2_2_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/3580305.3599461"},{"key":"e_1_3_2_2_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/3534678.3539357"},{"key":"e_1_3_2_2_34_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v36i4.20303"},{"key":"e_1_3_2_2_35_1","volume-title":"Word-level textual adversarial attacking as combinatorial optimization. arXiv preprint arXiv:1910.12196","author":"Zang Yuan","year":"2019","unstructured":"Yuan Zang, Fanchao Qi, Chenghao Yang, Zhiyuan Liu, Meng Zhang, Qun Liu, and Maosong Sun. 2019. Word-level textual adversarial attacking as combinatorial optimization. arXiv preprint arXiv:1910.12196 (2019), 1-10."},{"key":"e_1_3_2_2_36_1","first-page":"1","volume-title":"Proceedings of the 28th Advances in Neural Information Processing Systems","author":"Zhang Xiang","year":"2015","unstructured":"Xiang Zhang, Junbo Zhao, and Yann LeCun. 2015. Character-level convolutional networks for text classification. In Proceedings of the 28th Advances in Neural Information Processing Systems. Quebec, Canada, 1-8."},{"key":"e_1_3_2_2_37_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i17.29950"}],"event":{"name":"KDD '25: The 31st ACM SIGKDD Conference on Knowledge Discovery and Data Mining","location":"Toronto ON Canada","acronym":"KDD '25","sponsor":["SIGKDD ACM Special Interest Group on Knowledge Discovery in Data","SIGMOD ACM Special Interest Group on Management of Data"]},"container-title":["Proceedings of the 31st ACM SIGKDD Conference on Knowledge Discovery and Data Mining V.2"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3711896.3736946","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,30]],"date-time":"2026-04-30T18:11:45Z","timestamp":1777572705000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3711896.3736946"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,8,3]]},"references-count":37,"alternative-id":["10.1145\/3711896.3736946","10.1145\/3711896"],"URL":"https:\/\/doi.org\/10.1145\/3711896.3736946","relation":{},"subject":[],"published":{"date-parts":[[2025,8,3]]},"assertion":[{"value":"2025-08-03","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}