{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/improving-query-efficiency-of-black-box-1","title":"Improving Query Efficiency of Black-box Adversarial Attack","arxiv_id":"2009.11508","date":"2020-09-24","proceeding":"ECCV 2020 8","authors":["Yang Bai","Yuyuan Zeng","Yong Jiang","Yisen Wang","Shu-Tao Xia","Weiwei Guo"],"abstract":"Deep neural networks (DNNs) have demonstrated excellent performance on various tasks, however they are under the risk of adversarial examples that can be easily generated when the target model is accessible to an attacker (white-box setting). As plenty of machine learning models have been deployed via online services that only provide query outputs from inaccessible models (e.g. Google Cloud Vision API2), black-box adversarial attacks (inaccessible target model) are of critical security concerns in practice rather than white-box ones. However, existing query-based black-box adversarial attacks often require excessive model queries to maintain a high attack success rate. Therefore, in order to improve query efficiency, we explore the distribution of adversarial examples around benign inputs with the help of image structure information characterized by a Neural Process, and propose a Neural Process based black-box adversarial attack (NP-Attack) in this paper. Extensive experiments show that NP-Attack could greatly decrease the query counts under the black-box setting.","url_abs":"https://arxiv.org/abs/2009.11508v2","url_pdf":"https://arxiv.org/pdf/2009.11508v2.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"improving-query-efficiency-of-black-box-1","repo_url":"https://github.com/Sandy-Zeng/NPAttack","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":0,"framework":"pytorch","reach":null}],"tasks":[{"task_slug":"adversarial-attack","task_name":"Adversarial Attack"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":"https://syntology.ai/paper/2009.11508","atlas_url":"https://app.syntology.ai/?focus=2009.11508","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2009.11508"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-25T09:33:49+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/Sandy-Zeng/NPAttack","reach":null}],"summary":{"unverified":2},"by_repo_kind":{"official":{"samples":2,"ran":0,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":2,"samples":[{"code_sha256_prefix":"705a6ab5b983b4ee","entry":"generate_grid","repo":"Sandy-Zeng/NPAttack","repo_kind":"official","path":"NPAttack_IMAGENET.py","file_url":"https://github.com/Sandy-Zeng/NPAttack/blob/HEAD/NPAttack_IMAGENET.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"705a6ab5b983b4ee"}},{"code_sha256_prefix":"43cb3c2e96f81465","entry":"upsample","repo":"Sandy-Zeng/NPAttack","repo_kind":"official","path":"NPAttack_IMAGENET.py","file_url":"https://github.com/Sandy-Zeng/NPAttack/blob/HEAD/NPAttack_IMAGENET.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"43cb3c2e96f81465"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}