{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/hybrid-batch-attacks-finding-black-box","title":"Hybrid Batch Attacks: Finding Black-box Adversarial Examples with Limited Queries","arxiv_id":"1908.07000","date":"2019-08-19","proceeding":null,"authors":["Fnu Suya","Jianfeng Chi","David Evans","Yuan Tian"],"abstract":"We study adversarial examples in a black-box setting where the adversary only has API access to the target model and each query is expensive. Prior work on black-box adversarial examples follows one of two main strategies: (1) transfer attacks use white-box attacks on local models to find candidate adversarial examples that transfer to the target model, and (2) optimization-based attacks use queries to the target model and apply optimization techniques to search for adversarial examples. We propose hybrid attacks that combine both strategies, using candidate adversarial examples from local models as starting points for optimization-based attacks and using labels learned in optimization-based attacks to tune local models for finding transfer candidates. We empirically demonstrate on the MNIST, CIFAR10, and ImageNet datasets that our hybrid attack strategy reduces cost and improves success rates. We also introduce a seed prioritization strategy which enables attackers to focus their resources on the most promising seeds. Combining hybrid attacks with our seed prioritization strategy enables batch attacks that can reliably find adversarial examples with only a handful of queries.","url_abs":"https://arxiv.org/abs/1908.07000v1","url_pdf":"https://arxiv.org/pdf/1908.07000v1.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"links_only","authors_date_abstract":"arXiv metadata, CC0 1.0 (https://info.arxiv.org/help/license), from the Kaggle arXiv metadata snapshot of 2026-09-12"},"code_links":[{"paper_slug":"hybrid-batch-attacks-finding-black-box","repo_url":"https://github.com/suyeecav/Hybrid-Attack","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":1,"framework":"tf","reach":{"status":"ok","spdx":"BSD-2-Clause"}}],"tasks":[],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=1908.07000","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1908.07000"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-24T18:15:14+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/suyeecav/Hybrid-Attack","reach":{"status":"ok","spdx":"BSD-2-Clause"}}],"summary":{"unverified":5},"by_repo_kind":{"official":{"samples":5,"ran":0,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":0,"samples":[{"code_sha256_prefix":"96a4f54dd113814a","entry":"autozoom_attack","repo":"suyeecav/Hybrid-Attack","repo_kind":"official","path":"cifar10/attack_utils.py","file_url":"https://github.com/suyeecav/Hybrid-Attack/blob/HEAD/cifar10/attack_utils.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"BSD-2-Clause","inline_ok":true,"mcp_get_code":{"code_sha256":"96a4f54dd113814a"}},{"code_sha256_prefix":"bae2f8454caddf87","entry":"get_grad_np","repo":"suyeecav/Hybrid-Attack","repo_kind":"official","path":"cifar10/attack_utils.py","file_url":"https://github.com/suyeecav/Hybrid-Attack/blob/HEAD/cifar10/attack_utils.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"BSD-2-Clause","inline_ok":true,"mcp_get_code":{"code_sha256":"bae2f8454caddf87"}},{"code_sha256_prefix":"2107d80a396372c3","entry":"get_grad_np","repo":"suyeecav/Hybrid-Attack","repo_kind":"official","path":"imagenet/nes/attack_utils.py","file_url":"https://github.com/suyeecav/Hybrid-Attack/blob/HEAD/imagenet/nes/attack_utils.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"BSD-2-Clause","inline_ok":true,"mcp_get_code":{"code_sha256":"2107d80a396372c3"}},{"code_sha256_prefix":"e0d1096de0075343","entry":"get_grad_np","repo":"suyeecav/Hybrid-Attack","repo_kind":"official","path":"mnist/attack_utils.py","file_url":"https://github.com/suyeecav/Hybrid-Attack/blob/HEAD/mnist/attack_utils.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"BSD-2-Clause","inline_ok":true,"mcp_get_code":{"code_sha256":"e0d1096de0075343"}},{"code_sha256_prefix":"f1e19996b0c68945","entry":"nes_attack","repo":"suyeecav/Hybrid-Attack","repo_kind":"official","path":"cifar10/attack_utils.py","file_url":"https://github.com/suyeecav/Hybrid-Attack/blob/HEAD/cifar10/attack_utils.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"BSD-2-Clause","inline_ok":true,"mcp_get_code":{"code_sha256":"f1e19996b0c68945"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}