{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/unrestricted-adversarial-attacks-on-imagenet","title":"Unrestricted Adversarial Attacks on ImageNet Competition","arxiv_id":"2110.09903","date":"2021-10-17","proceeding":null,"authors":["Yuefeng Chen","Xiaofeng Mao","Yuan He","Hui Xue","Chao Li","Yinpeng Dong","Qi-An Fu","Xiao Yang","Tianyu Pang","Hang Su","Jun Zhu","Fangcheng Liu","Chao Zhang","Hongyang Zhang","Yichi Zhang","Shilong Liu","Chang Liu","Wenzhao Xiang","Yajie Wang","Huipeng Zhou","Haoran Lyu","Yidan Xu","Zixuan Xu","Taoyu Zhu","Wenjun Li","Xianfeng Gao","Guoqiu Wang","Huanqian Yan","Ying Guo","Chaoning Zhang","Zheng Fang","Yang Wang","Bingyang Fu","Yunfei Zheng","Yekui Wang","Haorong Luo","Zhen Yang"],"abstract":"Many works have investigated the adversarial attacks or defenses under the settings where a bounded and imperceptible perturbation can be added to the input. However in the real-world, the attacker does not need to comply with this restriction. In fact, more threats to the deep model come from unrestricted adversarial examples, that is, the attacker makes large and visible modifications on the image, which causes the model classifying mistakenly, but does not affect the normal observation in human perspective. Unrestricted adversarial attack is a popular and practical direction but has not been studied thoroughly. We organize this competition with the purpose of exploring more effective unrestricted adversarial attack algorithm, so as to accelerate the academical research on the model robustness under stronger unbounded attacks. The competition is held on the TianChi platform (\\url{https://tianchi.aliyun.com/competition/entrance/531853/introduction}) as one of the series of AI Security Challengers Program.","url_abs":"https://arxiv.org/abs/2110.09903v2","url_pdf":"https://arxiv.org/pdf/2110.09903v2.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"unrestricted-adversarial-attacks-on-imagenet","repo_url":"https://github.com/Equationliu/GA-Attack","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"pytorch","reach":null}],"tasks":[{"task_slug":"adversarial-attack","task_name":"Adversarial Attack"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=2110.09903","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2110.09903"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-24T18:15:14+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/Equationliu/GA-Attack","reach":null}],"summary":{"ran_fixture":2},"by_repo_kind":{"listed":{"samples":1,"ran":1,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":1,"samples":[{"code_sha256_prefix":"6274323448783615","entry":"moments","repo":"Equationliu/GA-Attack","repo_kind":"listed","path":"attacks/feature.py","file_url":"https://github.com/Equationliu/GA-Attack/blob/HEAD/attacks/feature.py","link_basis":"first_harvest_node","language":"python","status":"ran_fixture","verification_level":1,"contract_check":"RAISES","metamorphic_tier":"invariant","behaviour_fingerprint":true,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"6274323448783615"}},{"code_sha256_prefix":"65e1c0ed365fa761","entry":"reduce_tensor","repo":null,"repo_kind":null,"path":null,"file_url":null,"link_basis":"identical_code_first_harvested_elsewhere","language":"python","status":"ran_fixture","verification_level":1,"contract_check":"RAISES","metamorphic_tier":"invariant","behaviour_fingerprint":false,"licence":null,"inline_ok":false,"mcp_get_code":{"code_sha256":"65e1c0ed365fa761"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}