{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/square-attack-a-query-efficient-black-box","title":"Square Attack: a query-efficient black-box adversarial attack via random search","arxiv_id":"1912.00049","date":"2019-11-29","proceeding":"ECCV 2020 8","authors":["Maksym Andriushchenko","Francesco Croce","Nicolas Flammarion","Matthias Hein"],"abstract":"We propose the Square Attack, a score-based black-box $l_2$- and $l_\\infty$-adversarial attack that does not rely on local gradient information and thus is not affected by gradient masking. Square Attack is based on a randomized search scheme which selects localized square-shaped updates at random positions so that at each iteration the perturbation is situated approximately at the boundary of the feasible set. Our method is significantly more query efficient and achieves a higher success rate compared to the state-of-the-art methods, especially in the untargeted setting. In particular, on ImageNet we improve the average query efficiency in the untargeted setting for various deep networks by a factor of at least $1.8$ and up to $3$ compared to the recent state-of-the-art $l_\\infty$-attack of Al-Dujaili & O'Reilly. Moreover, although our attack is black-box, it can also outperform gradient-based white-box attacks on the standard benchmarks achieving a new state-of-the-art in terms of the success rate. The code of our attack is available at https://github.com/max-andr/square-attack.","url_abs":"https://arxiv.org/abs/1912.00049v3","url_pdf":"https://arxiv.org/pdf/1912.00049v3.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"square-attack-a-query-efficient-black-box","repo_url":"https://github.com/max-andr/square-attack","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":1,"framework":"tf","reach":null},{"paper_slug":"square-attack-a-query-efficient-black-box","repo_url":"https://github.com/timroith/adversarialcbo","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"pytorch","reach":null}],"tasks":[{"task_slug":"adversarial-attack","task_name":"Adversarial Attack"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":"https://syntology.ai/paper/1912.00049","atlas_url":"https://app.syntology.ai/?focus=1912.00049","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1912.00049"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-25T09:33:49+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/timroith/adversarialcbo","reach":null},{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/max-andr/square-attack","reach":null}],"summary":{"ran_honours":3},"by_repo_kind":{"official":{"samples":3,"ran":3,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":0,"samples":[{"code_sha256_prefix":"4ca7ef6d76dc7319","entry":"meta_pseudo_gaussian_pert","repo":"max-andr/square-attack","repo_kind":"official","path":"attack.py","file_url":"https://github.com/max-andr/square-attack/blob/HEAD/attack.py","link_basis":"first_harvest_node","language":"python","status":"ran_honours","verification_level":1,"contract_check":"HONOURS","metamorphic_tier":"well_formed","behaviour_fingerprint":true,"licence":"BSD-3-Clause","inline_ok":true,"mcp_get_code":{"code_sha256":"4ca7ef6d76dc7319"}},{"code_sha256_prefix":"053d874dd6c8872d","entry":"p_selection","repo":"max-andr/square-attack","repo_kind":"official","path":"attack.py","file_url":"https://github.com/max-andr/square-attack/blob/HEAD/attack.py","link_basis":"first_harvest_node","language":"python","status":"ran_honours","verification_level":1,"contract_check":"HONOURS","metamorphic_tier":"well_formed","behaviour_fingerprint":true,"licence":"BSD-3-Clause","inline_ok":true,"mcp_get_code":{"code_sha256":"053d874dd6c8872d"}},{"code_sha256_prefix":"c7544861060c462d","entry":"pseudo_gaussian_pert_rectangles","repo":"max-andr/square-attack","repo_kind":"official","path":"attack.py","file_url":"https://github.com/max-andr/square-attack/blob/HEAD/attack.py","link_basis":"first_harvest_node","language":"python","status":"ran_honours","verification_level":1,"contract_check":"HONOURS","metamorphic_tier":"well_formed","behaviour_fingerprint":true,"licence":"BSD-3-Clause","inline_ok":true,"mcp_get_code":{"code_sha256":"c7544861060c462d"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}