{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/code/attack-2","entry":"Attack","source":"Syntology graph, per-sample; not an archive number","read_at":"2026-09-24T18:15:14+00:00","claim":"Names are grouped by exact entry-name string. Same-named routines are NOT asserted to be equivalent; 'ran' means executed on a synthesized fixture, not correctness. n_samples_ran = sum of by_status over every status except 'unverified' (ran_draft_wrong and ran_fixture are failures of Syntology's instrument, not of the code); n_papers_ran = papers with at least one such sample.","status_vocabulary":{"ran_honours":"ran, honoured the contract we drafted","ran_violates":"ran, violated the contract we drafted","ran_draft_wrong":"ran; our contract draft was wrong, not the code","ran_fixture":"ran; our fixture could not drive it","ran":"ran on a synthesized input","unverified":"unverified (harvested, no recorded run)"},"n_papers":15,"n_papers_ran":8,"units":"n_samples, n_samples_ran, n_samples_fingerprinted and by_status count distinct code bodies (code_sha256); n_places and n_places_pointer_only count places, one per (paper, code body) pair, which is also the unit of the samples list","n_samples":15,"n_samples_ran":8,"n_samples_fingerprinted":0,"n_places":15,"n_places_pointer_only":4,"by_status":{"ran_honours":0,"ran_violates":0,"ran_draft_wrong":0,"ran_fixture":0,"ran":8,"unverified":7},"syntology":{"atlas_url":null,"mcp":null,"mcp_per_sample":{"tool":"get_code","arguments_in":"samples[].mcp_get_code"},"developers":"https://syntology.ai/developers"},"samples":[{"arxiv_id":"2608.21577","paper":"/paper/arxiv-2608-21577","title":"Anchoring Bias: A Persistent Fairness Backdoor Attack against MLLMs under Continual Learning","date":null,"month_inferred_from_arxiv_id":"2026-08","title_source":"syntology","repo":"lyygua/PFBA","path":"src/trigger_optim.py","file_url":"https://github.com/lyygua/PFBA/blob/HEAD/src/trigger_optim.py","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"code_sha256_prefix":"8da0f4f301f355a1","mcp_get_code":{"code_sha256":"8da0f4f301f355a1"}},{"arxiv_id":"2508.20718","paper":"/paper/arxiv-2508-20718","title":"Addressing Tokenization Inconsistency in Steganography and Watermarking Based on Large Language Models","date":null,"month_inferred_from_arxiv_id":"2025-08","title_source":"syntology","repo":"ryehr/Consistency","path":"legacy/Attack_watermark.py","file_url":"https://github.com/ryehr/Consistency/blob/HEAD/legacy/Attack_watermark.py","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"code_sha256_prefix":"4641dca1ac6eb907","mcp_get_code":{"code_sha256":"4641dca1ac6eb907"}},{"arxiv_id":"2501.17151","paper":"/paper/scanning-trojaned-models-using-out-of","title":"Scanning Trojaned Models Using Out-of-Distribution Samples","date":"2025-01-28","month_inferred_from_arxiv_id":null,"title_source":"archive","repo":"rohban-lab/trodo","path":"src/evaluate.py","file_url":"https://github.com/rohban-lab/trodo/blob/HEAD/src/evaluate.py","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"code_sha256_prefix":"2e0cda14736613a9","mcp_get_code":{"code_sha256":"2e0cda14736613a9"}},{"arxiv_id":"2405.19074","paper":"/paper/resurrecting-old-classes-with-new-data-for","title":"Resurrecting Old Classes with New Data for Exemplar-Free Continual Learning","date":"2024-05-29","month_inferred_from_arxiv_id":null,"title_source":"archive","repo":"dipamgoswami/ADC","path":"utils/attack.py","file_url":"https://github.com/dipamgoswami/ADC/blob/HEAD/utils/attack.py","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"code_sha256_prefix":"a2e33094ba485ca1","mcp_get_code":{"code_sha256":"a2e33094ba485ca1"}},{"arxiv_id":"2405.14077","paper":"/paper/learning-to-transform-dynamically-for-better","title":"Learning to Transform Dynamically for Better Adversarial Transferability","date":"2024-05-23","month_inferred_from_arxiv_id":null,"title_source":"archive","repo":"rongyizhu/l2t","path":"l2t.py","file_url":"https://github.com/rongyizhu/l2t/blob/HEAD/l2t.py","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"code_sha256_prefix":"27a0edca5630cc99","mcp_get_code":{"code_sha256":"27a0edca5630cc99"}},{"arxiv_id":"2311.01441","paper":"/paper/distilling-out-of-distribution-robustness-1","title":"Distilling Out-of-Distribution Robustness from Vision-Language Foundation Models","date":"2023-11-02","month_inferred_from_arxiv_id":null,"title_source":"archive","repo":"lapisrocks/DiscreteAdversarialDistillation","path":"easyrobust/easyrobust/attacks/robustkdattack.py","file_url":"https://github.com/lapisrocks/DiscreteAdversarialDistillation/blob/HEAD/easyrobust/easyrobust/attacks/robustkdattack.py","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":"deterministic","behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"code_sha256_prefix":"84d8f5ac4eda7612","mcp_get_code":{"code_sha256":"84d8f5ac4eda7612"}},{"arxiv_id":"2309.14700","paper":"/paper/structure-invariant-transformation-for-better","title":"Structure Invariant Transformation for better Adversarial Transferability","date":"2023-09-26","month_inferred_from_arxiv_id":null,"title_source":"archive","repo":"xiaosen-wang/sit","path":"attack.py","file_url":"https://github.com/xiaosen-wang/sit/blob/HEAD/attack.py","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"code_sha256_prefix":"bebf460ad966151e","mcp_get_code":{"code_sha256":"bebf460ad966151e"}},{"arxiv_id":"2307.15043","paper":"/paper/universal-and-transferable-adversarial","title":"Universal and Transferable Adversarial Attacks on Aligned Language Models","date":"2023-07-27","month_inferred_from_arxiv_id":null,"title_source":"archive","repo":"arobey1/smooth-llm","path":"lib/attacks.py","file_url":"https://github.com/arobey1/smooth-llm/blob/HEAD/lib/attacks.py","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"code_sha256_prefix":"c8b60c98283b0f93","mcp_get_code":{"code_sha256":"c8b60c98283b0f93"}},{"arxiv_id":"2303.09962","paper":"/paper/adversarial-counterfactual-visual","title":"Adversarial Counterfactual Visual Explanations","date":"2023-03-17","month_inferred_from_arxiv_id":null,"title_source":"archive","repo":"guillaumejs2403/ace","path":"core/attacks_and_models.py","file_url":"https://github.com/guillaumejs2403/ace/blob/HEAD/core/attacks_and_models.py","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"code_sha256_prefix":"8861e9868b41a83f","mcp_get_code":{"code_sha256":"8861e9868b41a83f"}},{"arxiv_id":"2302.03015","paper":"/paper/exploring-and-exploiting-decision-boundary","title":"Exploring and Exploiting Decision Boundary Dynamics for Adversarial Robustness","date":"2023-02-06","month_inferred_from_arxiv_id":null,"title_source":"archive","repo":"yuancheng-xu/dynamics-aware-robust-training","path":"core/DyART/DyART_Linf.py","file_url":"https://github.com/yuancheng-xu/dynamics-aware-robust-training/blob/HEAD/core/DyART/DyART_Linf.py","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"code_sha256_prefix":"b5c1ada412a147f0","mcp_get_code":{"code_sha256":"b5c1ada412a147f0"}},{"arxiv_id":"2302.02213","paper":"/paper/cospgd-a-unified-white-box-adversarial-attack","title":"CosPGD: an efficient white-box adversarial attack for pixel-wise prediction tasks","date":"2023-02-04","month_inferred_from_arxiv_id":null,"title_source":"archive","repo":"shashankskagnihotri/cospgd","path":"cospgd/attack_implementations.py","file_url":"https://github.com/shashankskagnihotri/cospgd/blob/HEAD/cospgd/attack_implementations.py","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"code_sha256_prefix":"7623a5c36c266a4b","mcp_get_code":{"code_sha256":"7623a5c36c266a4b"}},{"arxiv_id":"2210.05968","paper":"/paper/boosting-the-transferability-of-adversarial-2","title":"Boosting the Transferability of Adversarial Attacks with Reverse Adversarial Perturbation","date":"2022-10-12","month_inferred_from_arxiv_id":null,"title_source":"archive","repo":"Trustworthy-AI-Group/TransferAttack","path":"transferattack/gradient/rap.py","file_url":"https://github.com/Trustworthy-AI-Group/TransferAttack/blob/HEAD/transferattack/gradient/rap.py","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"code_sha256_prefix":"01110864c3d8eec8","mcp_get_code":{"code_sha256":"01110864c3d8eec8"}},{"arxiv_id":"2210.03297","paper":"/paper/preprocessors-matter-realistic-decision-based","title":"Preprocessors Matter! Realistic Decision-Based Attacks on Machine Learning Systems","date":"2022-10-07","month_inferred_from_arxiv_id":null,"title_source":"archive","repo":"google-research/preprocessor-aware-black-box-attack","path":"attack_prep/attack/opt.py","file_url":"https://github.com/google-research/preprocessor-aware-black-box-attack/blob/HEAD/attack_prep/attack/opt.py","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"Apache-2.0","inline_ok":true,"code_sha256_prefix":"d9d87c3e7fb8c45f","mcp_get_code":{"code_sha256":"d9d87c3e7fb8c45f"}},{"arxiv_id":"2106.07445","paper":"/paper/popskipjump-decision-based-attack-for","title":"PopSkipJump: Decision-Based Attack for Probabilistic Classifiers","date":"2021-06-14","month_inferred_from_arxiv_id":null,"title_source":"archive","repo":"cjsg/PopSkipJump","path":"popskip.py","file_url":"https://github.com/cjsg/PopSkipJump/blob/HEAD/popskip.py","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"code_sha256_prefix":"b479fbfa86533c1b","mcp_get_code":{"code_sha256":"b479fbfa86533c1b"}},{"arxiv_id":"1901.08573","paper":"/paper/theoretically-principled-trade-off-between","title":"Theoretically Principled Trade-off between Robustness and Accuracy","date":"2019-01-24","month_inferred_from_arxiv_id":null,"title_source":"archive","repo":"arobey1/advbench","path":"advbench/algorithms.py","file_url":"https://github.com/arobey1/advbench/blob/HEAD/advbench/algorithms.py","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"code_sha256_prefix":"bca439beb127432f","mcp_get_code":{"code_sha256":"bca439beb127432f"}}]}