{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/zoo-zeroth-order-optimization-based-black-box","title":"ZOO: Zeroth Order Optimization based Black-box Attacks to Deep Neural Networks without Training Substitute Models","arxiv_id":"1708.03999","date":"2017-08-14","proceeding":null,"authors":["Pin-Yu Chen","huan zhang","Yash Sharma","Jin-Feng Yi","Cho-Jui Hsieh"],"abstract":"Deep neural networks (DNNs) are one of the most prominent technologies of our\ntime, as they achieve state-of-the-art performance in many machine learning\ntasks, including but not limited to image classification, text mining, and\nspeech processing. However, recent research on DNNs has indicated\never-increasing concern on the robustness to adversarial examples, especially\nfor security-critical tasks such as traffic sign identification for autonomous\ndriving. Studies have unveiled the vulnerability of a well-trained DNN by\ndemonstrating the ability of generating barely noticeable (to both human and\nmachines) adversarial images that lead to misclassification. Furthermore,\nresearchers have shown that these adversarial images are highly transferable by\nsimply training and attacking a substitute model built upon the target model,\nknown as a black-box attack to DNNs.\n  Similar to the setting of training substitute models, in this paper we\npropose an effective black-box attack that also only has access to the input\n(images) and the output (confidence scores) of a targeted DNN. However,\ndifferent from leveraging attack transferability from substitute models, we\npropose zeroth order optimization (ZOO) based attacks to directly estimate the\ngradients of the targeted DNN for generating adversarial examples. We use\nzeroth order stochastic coordinate descent along with dimension reduction,\nhierarchical attack and importance sampling techniques to efficiently attack\nblack-box models. By exploiting zeroth order optimization, improved attacks to\nthe targeted DNN can be accomplished, sparing the need for training substitute\nmodels and avoiding the loss in attack transferability. Experimental results on\nMNIST, CIFAR10 and ImageNet show that the proposed ZOO attack is as effective\nas the state-of-the-art white-box attack and significantly outperforms existing\nblack-box attacks via substitute models.","url_abs":"http://arxiv.org/abs/1708.03999v2","url_pdf":"http://arxiv.org/pdf/1708.03999v2.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"zoo-zeroth-order-optimization-based-black-box","repo_url":"https://github.com/huanzhang12/ZOO-Attack","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":1,"framework":"tf","reach":{"status":"unanswered"}},{"paper_slug":"zoo-zeroth-order-optimization-based-black-box","repo_url":"https://github.com/IBM/Autozoom-Attack","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"tf","reach":{"status":"ok","spdx":"Apache-2.0"}},{"paper_slug":"zoo-zeroth-order-optimization-based-black-box","repo_url":"https://github.com/IBM/ZOO-Attack","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"tf","reach":null},{"paper_slug":"zoo-zeroth-order-optimization-based-black-box","repo_url":"https://github.com/as791/ZOO_Attack_PyTorch","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"pytorch","reach":{"status":"unanswered"}},{"paper_slug":"zoo-zeroth-order-optimization-based-black-box","repo_url":"https://github.com/tuscan-chicken-wrap/ECE260FinalProject","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"tf","reach":{"status":"ok"}}],"tasks":[{"task_slug":"adversarial-attack","task_name":"Adversarial Attack"},{"task_slug":"adversarial-defense","task_name":"Adversarial Defense"},{"task_slug":"autonomous-driving","task_name":"Autonomous Driving"},{"task_slug":"dimensionality-reduction","task_name":"Dimensionality Reduction"},{"task_slug":"image-classification","task_name":"Image Classification"},{"task_slug":"image-classification","task_name":"image-classification"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=1708.03999","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1708.03999"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-24T18:15:14+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/IBM/Autozoom-Attack","reach":{"status":"ok","spdx":"Apache-2.0"}},{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/as791/ZOO_Attack_PyTorch","reach":{"status":"unanswered"}},{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/IBM/ZOO-Attack","reach":null},{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/tuscan-chicken-wrap/ECE260FinalProject","reach":{"status":"ok"}},{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/huanzhang12/ZOO-Attack","reach":{"status":"unanswered"}}],"summary":{"ran_draft_wrong":1},"by_repo_kind":{"listed":{"samples":1,"ran":1,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":0,"samples":[{"code_sha256_prefix":"3abcf522eaf4f685","entry":"generate_data","repo":"IBM/ZOO-Attack","repo_kind":"listed","path":"test_all.py","file_url":"https://github.com/IBM/ZOO-Attack/blob/HEAD/test_all.py","link_basis":"first_harvest_node","language":"python","status":"ran_draft_wrong","verification_level":1,"contract_check":"OUTPUT_MISDECLARED","metamorphic_tier":"deterministic","behaviour_fingerprint":false,"licence":"Apache-2.0","inline_ok":true,"mcp_get_code":{"code_sha256":"3abcf522eaf4f685"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}