{"about":{"non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","site":"https://codewithpapers.app","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page","syntology":{"site":"https://syntology.ai","developers":"https://syntology.ai/developers","mcp":{"server":"https://syntology.ai/mcp","transport":"streamable-http","server_card":"https://syntology.ai/.well-known/mcp/server-card.json","auth":{"type":"trial token, no account","trial_token":"https://syntology.ai/api/oauth/trial/token","method":"POST","docs":"https://syntology.ai/developers"}},"have":"https://syntology.ai/api/graph/have?x=<method, arXiv id or title> (free, answers coverage only)","paper_base":"https://syntology.ai/paper/","atlas_base":"https://app.syntology.ai/?focus="},"machine_readable":[{"url":"https://codewithpapers.app/llms.txt","what":"the machine catalog: every machine-readable file, counted"},{"url":"https://codewithpapers.app/index/manifest.json","what":"paper-to-code index by arXiv id, with Syntology's counts"},{"url":"https://codewithpapers.app/search/manifest.json","what":"site search index (titles, authors) and its files"},{"url":"https://codewithpapers.app/download","what":"bulk files: Syntology's layer, described there"},{"url":"https://codewithpapers.app/build_manifest.json","what":"the build record: inputs, counts, exclusions, probes"}]},"url":"/task/adversarial-attack/papers/6","list_of":"/task/adversarial-attack","task":"Adversarial Attack","archive":{"snapshot":"2025-07-28"},"key_notes":{"n_ran_checked":"legacy name, kept unchanged so existing readers do not break: it counts the samples that ran with no instrument failure (honoured, violated, and ran with no contract checked); it does not mean a contract was checked, and the pages print it as 'K with no instrument failure', not 'K checked'","n_constructed":"a sub-count of the samples that ran, never subtracted from them and never a failure: an executed sample whose run returned an instance of its own class (fixture_out_type equals the entry name): the run built an object and did not compute a result (Syntology's RAN record, counts.constructed)"},"syntology_read_at":"2026-09-28T10:30:06+00:00","order":"archive","order_definition":"repositories listed in the archive (most first), then date (newest first), then slug","page":6,"pages_in_order":19,"rows_per_page":100,"rows":[501,600],"of":1808,"counts":{"archive_papers_tagged":1808,"with_a_code_link":745,"where_syntology_ran_a_sample":206,"not_listed_spam_title":0,"listed":1808,"listed_where_code_ran":206,"where_syntology_ran_a_sample_split":{"with_a_run_with_no_instrument_failure":161,"every_run_a_failure_of_syntologys_instrument":45,"listed_with_a_run_with_no_instrument_failure":161,"listed_every_run_a_failure_of_syntologys_instrument":45,"filter":{"states":["a run with no instrument failure","any run, instrument failures included"],"default":"a run with no instrument failure","note":"on the 'only where code ran' pages the default hides, in the browser, the rows where every run was a failure of Syntology's instrument; the second state shows them again. Rows are hidden, never re-ordered; these twins list every row"}},"definition":"distinct papers the archive tags; 'where Syntology ran a sample' counts papers with at least one harvested sample that ran, which is not a correctness claim"},"first_page":"/task/adversarial-attack","prev":"/task/adversarial-attack/papers/5","next":"/task/adversarial-attack/papers/7","papers":[{"url":"/paper/black-box-adversarial-attacks-on-network-wide","slug":"black-box-adversarial-attacks-on-network-wide","title":"Black-box Adversarial Attacks on Network-wide Multi-step Traffic State Prediction Models","date":"2021-10-17","arxiv_id":"2110.08712","repositories_listed":1,"syntology":null},{"url":"/paper/unrestricted-adversarial-attacks-on-imagenet","slug":"unrestricted-adversarial-attacks-on-imagenet","title":"Unrestricted Adversarial Attacks on ImageNet Competition","date":"2021-10-17","arxiv_id":"2110.09903","repositories_listed":1,"syntology":{"n":2,"n_ran":2,"n_constructed":0,"n_ran_checked":0,"n_instrument":2,"n_unverified":0,"n_honours":0,"n_violates":0,"n_no_contract":0,"n_pointer_only":1,"phrase":"2 ran (of which 0 constructed an object rather than computing a result; 0 with no instrument failure: 0 honoured, 0 violated, 0 with no contract checked; 2 where Syntology's instrument failed) · 0 unverified","sample_list":"/paper/unrestricted-adversarial-attacks-on-imagenet#ran","syntology_url":"https://syntology.ai/paper/2110.09903","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2110.09903"}},"official":null}},{"url":"/paper/adversarial-attacks-on-gaussian-process","slug":"adversarial-attacks-on-gaussian-process","title":"Adversarial Attacks on Gaussian Process Bandits","date":"2021-10-16","arxiv_id":"2110.08449","repositories_listed":1,"syntology":{"n":6,"n_ran":1,"n_constructed":0,"n_ran_checked":1,"n_instrument":0,"n_unverified":5,"n_honours":0,"n_violates":0,"n_no_contract":1,"n_pointer_only":0,"phrase":"1 ran (of which 0 constructed an object rather than computing a result; 1 with no instrument failure: 0 honoured, 0 violated, 1 with no contract checked; 0 where Syntology's instrument failed) · 5 unverified","sample_list":"/paper/adversarial-attacks-on-gaussian-process#ran","syntology_url":"https://syntology.ai/paper/2110.08449","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2110.08449"}},"official":{"repos":["eric-vader/attack-bo"],"state":"official (archive's flag): 1 ran","n_ran":1,"n_constructed":0,"n_ran_no_instrument_failure":1,"n_unverified":5,"ran_from_kinds":["official"]}}},{"url":"/paper/adversarial-attacks-on-ml-defense-models","slug":"adversarial-attacks-on-ml-defense-models","title":"Adversarial Attacks on ML Defense Models Competition","date":"2021-10-15","arxiv_id":"2110.08042","repositories_listed":1,"syntology":null},{"url":"/paper/mind-the-style-of-text-adversarial-and","slug":"mind-the-style-of-text-adversarial-and","title":"Mind the Style of Text! Adversarial and Backdoor Attacks Based on Text Style Transfer","date":"2021-10-14","arxiv_id":"2110.07139","repositories_listed":1,"syntology":{"n":1,"n_ran":0,"n_constructed":0,"n_ran_checked":0,"n_instrument":0,"n_unverified":1,"n_honours":0,"n_violates":0,"n_no_contract":0,"n_pointer_only":0,"phrase":"0 ran · 1 unverified","sample_list":"/paper/mind-the-style-of-text-adversarial-and#ran","syntology_url":"https://syntology.ai/paper/2110.07139","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2110.07139"}},"official":{"repos":["thunlp/styleattack"],"state":"official: harvested, nothing ran","n_ran":0,"n_constructed":0,"n_ran_no_instrument_failure":0,"n_unverified":1,"ran_from_kinds":[]}}},{"url":"/paper/graph-fraudster-adversarial-attacks-on-graph","slug":"graph-fraudster-adversarial-attacks-on-graph","title":"Graph-Fraudster: Adversarial Attacks on Graph Neural Network Based Vertical Federated Learning","date":"2021-10-13","arxiv_id":"2110.06468","repositories_listed":1,"syntology":null},{"url":"/paper/evadedroid-a-practical-evasion-attack-on","slug":"evadedroid-a-practical-evasion-attack-on","title":"EvadeDroid: A Practical Evasion Attack on Machine Learning for Black-box Android Malware Detection","date":"2021-10-07","arxiv_id":"2110.03301","repositories_listed":1,"syntology":null},{"url":"/paper/a-uniform-framework-for-anomaly-detection-in","slug":"a-uniform-framework-for-anomaly-detection-in","title":"A Uniform Framework for Anomaly Detection in Deep Neural Networks","date":"2021-10-06","arxiv_id":"2110.03092","repositories_listed":1,"syntology":null},{"url":"/paper/adversarial-attacks-on-spiking-convolutional","slug":"adversarial-attacks-on-spiking-convolutional","title":"Adversarial Attacks on Spiking Convolutional Neural Networks for Event-based Vision","date":"2021-10-06","arxiv_id":"2110.02929","repositories_listed":1,"syntology":null},{"url":"/paper/adversarial-robustness-comparison-of-vision","slug":"adversarial-robustness-comparison-of-vision","title":"Adversarial Robustness Comparison of Vision Transformer and MLP-Mixer to CNNs","date":"2021-10-06","arxiv_id":"2110.02797","repositories_listed":1,"syntology":null},{"url":"/paper/attack-as-the-best-defense-nullifying-image-1","slug":"attack-as-the-best-defense-nullifying-image-1","title":"Attack as the Best Defense: Nullifying Image-to-image Translation GANs via Limit-aware Adversarial Attack","date":"2021-10-06","arxiv_id":"2110.02516","repositories_listed":1,"syntology":{"n":5,"n_ran":5,"n_constructed":0,"n_ran_checked":3,"n_instrument":2,"n_unverified":0,"n_honours":0,"n_violates":0,"n_no_contract":3,"n_pointer_only":2,"phrase":"5 ran (of which 0 constructed an object rather than computing a result; 3 with no instrument failure: 0 honoured, 0 violated, 3 with no contract checked; 2 where Syntology's instrument failed) · 0 unverified","sample_list":"/paper/attack-as-the-best-defense-nullifying-image-1#ran","syntology_url":"https://syntology.ai/paper/2110.02516","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2110.02516"}},"official":{"repos":["jimmy-academia/lasgsa"],"state":"official (archive's flag): 5 ran","n_ran":5,"n_constructed":0,"n_ran_no_instrument_failure":3,"n_unverified":0,"ran_from_kinds":["official"]}}},{"url":"/paper/neural-network-adversarial-attack-method","slug":"neural-network-adversarial-attack-method","title":"An Improved Genetic Algorithm and Its Application in Neural Network Adversarial Attack","date":"2021-10-05","arxiv_id":"2110.01818","repositories_listed":1,"syntology":null},{"url":"/paper/query-based-adversarial-attacks-on-graph-with","slug":"query-based-adversarial-attacks-on-graph-with","title":"Cluster Attack: Query-based Adversarial Attacks on Graphs with Graph-Dependent Priors","date":"2021-09-27","arxiv_id":"2109.13069","repositories_listed":1,"syntology":null},{"url":"/paper/breaking-bert-understanding-its","slug":"breaking-bert-understanding-its","title":"Breaking BERT: Understanding its Vulnerabilities for Named Entity Recognition through Adversarial Attack","date":"2021-09-23","arxiv_id":"2109.11308","repositories_listed":1,"syntology":null},{"url":"/paper/fca-learning-a-3d-full-coverage-vehicle","slug":"fca-learning-a-3d-full-coverage-vehicle","title":"FCA: Learning a 3D Full-coverage Vehicle Camouflage for Multi-view Physical Adversarial Attack","date":"2021-09-15","arxiv_id":"2109.07193","repositories_listed":1,"syntology":null},{"url":"/paper/petgen-personalized-text-generation-attack-on","slug":"petgen-personalized-text-generation-attack-on","title":"PETGEN: Personalized Text Generation Attack on Deep Sequence Embedding-based Classification Models","date":"2021-09-14","arxiv_id":"2109.06777","repositories_listed":1,"syntology":null},{"url":"/paper/multi-granularity-textual-adversarial-attack","slug":"multi-granularity-textual-adversarial-attack","title":"Multi-granularity Textual Adversarial Attack with Behavior Cloning","date":"2021-09-09","arxiv_id":"2109.04367","repositories_listed":1,"syntology":null},{"url":"/paper/excess-capacity-and-backdoor-poisoning","slug":"excess-capacity-and-backdoor-poisoning","title":"Excess Capacity and Backdoor Poisoning","date":"2021-09-02","arxiv_id":"2109.00685","repositories_listed":1,"syntology":{"n":3,"n_ran":3,"n_constructed":0,"n_ran_checked":3,"n_instrument":0,"n_unverified":0,"n_honours":0,"n_violates":0,"n_no_contract":3,"n_pointer_only":0,"phrase":"3 ran (of which 0 constructed an object rather than computing a result; 3 with no instrument failure: 0 honoured, 0 violated, 3 with no contract checked; 0 where Syntology's instrument failed) · 0 unverified","sample_list":"/paper/excess-capacity-and-backdoor-poisoning#ran","syntology_url":"https://syntology.ai/paper/2109.00685","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2109.00685"}},"official":{"repos":["narenmanoj/mnist-adv-training"],"state":"official: no sample here; runs from other or unrecorded repositories","n_ran":0,"n_constructed":0,"n_ran_no_instrument_failure":0,"n_unverified":0,"ran_from_kinds":["found_in_text"]}}},{"url":"/paper/dropattack-a-masked-weight-adversarial","slug":"dropattack-a-masked-weight-adversarial","title":"DropAttack: A Masked Weight Adversarial Training Method to Improve Generalization of Neural Networks","date":"2021-08-29","arxiv_id":"2108.12805","repositories_listed":1,"syntology":null},{"url":"/paper/disrupting-adversarial-transferability-in","slug":"disrupting-adversarial-transferability-in","title":"Disrupting Adversarial Transferability in Deep Neural Networks","date":"2021-08-27","arxiv_id":"2108.12492","repositories_listed":1,"syntology":null},{"url":"/paper/advdrop-adversarial-attack-to-dnns-by","slug":"advdrop-adversarial-attack-to-dnns-by","title":"AdvDrop: Adversarial Attack to DNNs by Dropping Information","date":"2021-08-20","arxiv_id":"2108.09034","repositories_listed":1,"syntology":{"n":10,"n_ran":7,"n_constructed":0,"n_ran_checked":7,"n_instrument":0,"n_unverified":3,"n_honours":0,"n_violates":0,"n_no_contract":7,"n_pointer_only":0,"phrase":"7 ran (of which 0 constructed an object rather than computing a result; 7 with no instrument failure: 0 honoured, 0 violated, 7 with no contract checked; 0 where Syntology's instrument failed) · 3 unverified","sample_list":"/paper/advdrop-adversarial-attack-to-dnns-by#ran","syntology_url":"https://syntology.ai/paper/2108.09034","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2108.09034"}},"official":{"repos":["rjduan/advdrop"],"state":"official (archive's flag): 7 ran","n_ran":7,"n_constructed":0,"n_ran_no_instrument_failure":7,"n_unverified":3,"ran_from_kinds":["official"]}}},{"url":"/paper/amplitude-phase-recombination-rethinking","slug":"amplitude-phase-recombination-rethinking","title":"Amplitude-Phase Recombination: Rethinking Robustness of Convolutional Neural Networks in Frequency Domain","date":"2021-08-19","arxiv_id":"2108.08487","repositories_listed":1,"syntology":{"n":10,"n_ran":9,"n_constructed":0,"n_ran_checked":2,"n_instrument":7,"n_unverified":1,"n_honours":2,"n_violates":0,"n_no_contract":0,"n_pointer_only":0,"phrase":"9 ran (of which 0 constructed an object rather than computing a result; 2 with no instrument failure: 2 honoured, 0 violated, 0 with no contract checked; 7 where Syntology's instrument failed) · 1 unverified","sample_list":"/paper/amplitude-phase-recombination-rethinking#ran","syntology_url":"https://syntology.ai/paper/2108.08487","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2108.08487"}},"official":{"repos":["iCGY96/APR"],"state":"official (archive's flag): 9 ran","n_ran":9,"n_constructed":0,"n_ran_no_instrument_failure":2,"n_unverified":1,"ran_from_kinds":["official"]}}},{"url":"/paper/agkd-bml-defense-against-adversarial-attack","slug":"agkd-bml-defense-against-adversarial-attack","title":"AGKD-BML: Defense Against Adversarial Attack by Attention Guided Knowledge Distillation and Bi-directional Metric Learning","date":"2021-08-13","arxiv_id":"2108.06017","repositories_listed":1,"syntology":{"n":1,"n_ran":1,"n_constructed":0,"n_ran_checked":1,"n_instrument":0,"n_unverified":0,"n_honours":0,"n_violates":1,"n_no_contract":0,"n_pointer_only":1,"phrase":"1 ran (of which 0 constructed an object rather than computing a result; 1 with no instrument failure: 0 honoured, 1 violated, 0 with no contract checked; 0 where Syntology's instrument failed) · 0 unverified","sample_list":"/paper/agkd-bml-defense-against-adversarial-attack#ran","syntology_url":"https://syntology.ai/paper/2108.06017","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2108.06017"}},"official":{"repos":["hongw579/agkd-bml"],"state":"official (archive's flag): 1 ran","n_ran":1,"n_constructed":0,"n_ran_no_instrument_failure":1,"n_unverified":0,"ran_from_kinds":["official"]}}},{"url":"/paper/meta-gradient-adversarial-attack","slug":"meta-gradient-adversarial-attack","title":"Meta Gradient Adversarial Attack","date":"2021-08-09","arxiv_id":"2108.04204","repositories_listed":1,"syntology":null},{"url":"/paper/poison-ink-robust-and-invisible-backdoor","slug":"poison-ink-robust-and-invisible-backdoor","title":"Poison Ink: Robust and Invisible Backdoor Attack","date":"2021-08-05","arxiv_id":"2108.02488","repositories_listed":1,"syntology":{"n":2,"n_ran":1,"n_constructed":0,"n_ran_checked":0,"n_instrument":1,"n_unverified":1,"n_honours":0,"n_violates":0,"n_no_contract":0,"n_pointer_only":0,"phrase":"1 ran (of which 0 constructed an object rather than computing a result; 0 with no instrument failure: 0 honoured, 0 violated, 0 with no contract checked; 1 where Syntology's instrument failed) · 1 unverified","sample_list":"/paper/poison-ink-robust-and-invisible-backdoor#ran","syntology_url":"https://syntology.ai/paper/2108.02488","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2108.02488"}},"official":null}},{"url":"/paper/discriminator-free-generative-adversarial","slug":"discriminator-free-generative-adversarial","title":"Discriminator-Free Generative Adversarial Attack","date":"2021-07-20","arxiv_id":"2107.09225","repositories_listed":1,"syntology":null},{"url":"/paper/self-supervised-contrastive-learning-with","slug":"self-supervised-contrastive-learning-with","title":"Self-Supervised Contrastive Learning with Adversarial Perturbations for Defending Word Substitution-based Attacks","date":"2021-07-15","arxiv_id":"2107.07610","repositories_listed":1,"syntology":null},{"url":"/paper/using-bert-encoding-to-tackle-the-mad-lib","slug":"using-bert-encoding-to-tackle-the-mad-lib","title":"Using BERT Encoding to Tackle the Mad-lib Attack in SMS Spam Detection","date":"2021-07-13","arxiv_id":"2107.06400","repositories_listed":1,"syntology":null},{"url":"/paper/evoba-an-evolution-strategy-as-a-strong","slug":"evoba-an-evolution-strategy-as-a-strong","title":"EvoBA: An Evolution Strategy as a Strong Baseline forBlack-Box Adversarial Attacks","date":"2021-07-12","arxiv_id":"2107.05754","repositories_listed":1,"syntology":null},{"url":"/paper/noise-based-cyberattacks-generating-fake-p300","slug":"noise-based-cyberattacks-generating-fake-p300","title":"Noise-based cyberattacks generating fake P300 waves in brain–computer interfaces","date":"2021-07-10","arxiv_id":null,"repositories_listed":1,"syntology":null},{"url":"/paper/dvs-attacks-adversarial-attacks-on-dynamic","slug":"dvs-attacks-adversarial-attacks-on-dynamic","title":"DVS-Attacks: Adversarial Attacks on Dynamic Vision Sensors for Spiking Neural Networks","date":"2021-07-01","arxiv_id":"2107.00415","repositories_listed":1,"syntology":null},{"url":"/paper/attack-transferability-characterization-for","slug":"attack-transferability-characterization-for","title":"Attack Transferability Characterization for Adversarially Robust Multi-label Classification","date":"2021-06-29","arxiv_id":"2106.15360","repositories_listed":1,"syntology":null},{"url":"/paper/tdgia-effective-injection-attacks-on-graph","slug":"tdgia-effective-injection-attacks-on-graph","title":"TDGIA:Effective Injection Attacks on Graph Neural Networks","date":"2021-06-12","arxiv_id":"2106.06663","repositories_listed":1,"syntology":null},{"url":"/paper/adversarial-robustness-through-the-lens-of","slug":"adversarial-robustness-through-the-lens-of","title":"CausalAdv: Adversarial Robustness through the Lens of Causality","date":"2021-06-11","arxiv_id":"2106.06196","repositories_listed":1,"syntology":null},{"url":"/paper/sparse-and-imperceptible-adversarial-attack","slug":"sparse-and-imperceptible-adversarial-attack","title":"Sparse and Imperceptible Adversarial Attack via a Homotopy Algorithm","date":"2021-06-10","arxiv_id":"2106.06027","repositories_listed":1,"syntology":{"n":5,"n_ran":1,"n_constructed":0,"n_ran_checked":0,"n_instrument":1,"n_unverified":4,"n_honours":0,"n_violates":0,"n_no_contract":0,"n_pointer_only":3,"phrase":"1 ran (of which 0 constructed an object rather than computing a result; 0 with no instrument failure: 0 honoured, 0 violated, 0 with no contract checked; 1 where Syntology's instrument failed) · 4 unverified","sample_list":"/paper/sparse-and-imperceptible-adversarial-attack#ran","syntology_url":"https://syntology.ai/paper/2106.06027","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2106.06027"}},"official":{"repos":["VITA-Group/SparseADV_Homotopy"],"state":"official (archive's flag): 1 ran","n_ran":1,"n_constructed":0,"n_ran_no_instrument_failure":0,"n_unverified":4,"ran_from_kinds":["official"]}}},{"url":"/paper/adversarial-attack-and-defense-in-deep","slug":"adversarial-attack-and-defense-in-deep","title":"Adversarial Attack and Defense in Deep Ranking","date":"2021-06-07","arxiv_id":"2106.03614","repositories_listed":1,"syntology":null},{"url":"/paper/dynamically-disentangling-social-bias-from","slug":"dynamically-disentangling-social-bias-from","title":"Dynamically Disentangling Social Bias from Task-Oriented Representations with Adversarial Attack","date":"2021-06-01","arxiv_id":null,"repositories_listed":1,"syntology":null},{"url":"/paper/defending-pre-trained-language-models-from","slug":"defending-pre-trained-language-models-from","title":"Defending Pre-trained Language Models from Adversarial Word Substitutions Without Performance Sacrifice","date":"2021-05-30","arxiv_id":"2105.14553","repositories_listed":1,"syntology":null},{"url":"/paper/reducing-dnn-properties-to-enable","slug":"reducing-dnn-properties-to-enable","title":"Reducing DNN Properties to Enable Falsification with Adversarial Attacks","date":"2021-05-27","arxiv_id":null,"repositories_listed":1,"syntology":null},{"url":"/paper/cmua-watermark-a-cross-model-universal","slug":"cmua-watermark-a-cross-model-universal","title":"CMUA-Watermark: A Cross-Model Universal Adversarial Watermark for Combating Deepfakes","date":"2021-05-23","arxiv_id":"2105.10872","repositories_listed":1,"syntology":{"n":5,"n_ran":3,"n_constructed":0,"n_ran_checked":3,"n_instrument":0,"n_unverified":2,"n_honours":0,"n_violates":0,"n_no_contract":3,"n_pointer_only":0,"phrase":"3 ran (of which 0 constructed an object rather than computing a result; 3 with no instrument failure: 0 honoured, 0 violated, 3 with no contract checked; 0 where Syntology's instrument failed) · 2 unverified","sample_list":"/paper/cmua-watermark-a-cross-model-universal#ran","syntology_url":"https://syntology.ai/paper/2105.10872","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2105.10872"}},"official":{"repos":["vdigpku/cmua-watermark"],"state":"official (archive's flag): 3 ran","n_ran":3,"n_constructed":0,"n_ran_no_instrument_failure":3,"n_unverified":2,"ran_from_kinds":["official"]}}},{"url":"/paper/an-orthogonal-classifier-for-improving-the","slug":"an-orthogonal-classifier-for-improving-the","title":"An Orthogonal Classifier for Improving the Adversarial Robustness of Neural Networks","date":"2021-05-19","arxiv_id":"2105.09109","repositories_listed":1,"syntology":{"n":7,"n_ran":5,"n_constructed":0,"n_ran_checked":5,"n_instrument":0,"n_unverified":2,"n_honours":0,"n_violates":0,"n_no_contract":5,"n_pointer_only":0,"phrase":"5 ran (of which 0 constructed an object rather than computing a result; 5 with no instrument failure: 0 honoured, 0 violated, 5 with no contract checked; 0 where Syntology's instrument failed) · 2 unverified","sample_list":"/paper/an-orthogonal-classifier-for-improving-the#ran","syntology_url":"https://syntology.ai/paper/2105.09109","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2105.09109"}},"official":{"repos":["MTandHJ/roboc"],"state":"official (archive's flag): 5 ran","n_ran":5,"n_constructed":0,"n_ran_no_instrument_failure":5,"n_unverified":2,"ran_from_kinds":["official"]}}},{"url":"/paper/local-aggressive-adversarial-attacks-on-3d","slug":"local-aggressive-adversarial-attacks-on-3d","title":"Local Aggressive Adversarial Attacks on 3D Point Cloud","date":"2021-05-19","arxiv_id":"2105.09090","repositories_listed":1,"syntology":{"n":1,"n_ran":0,"n_constructed":0,"n_ran_checked":0,"n_instrument":0,"n_unverified":1,"n_honours":0,"n_violates":0,"n_no_contract":0,"n_pointer_only":1,"phrase":"0 ran · 1 unverified","sample_list":"/paper/local-aggressive-adversarial-attacks-on-3d#ran","syntology_url":"https://syntology.ai/paper/2105.09090","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2105.09090"}},"official":{"repos":["Chenfeng1271/L3A"],"state":"official: harvested, nothing ran","n_ran":0,"n_constructed":0,"n_ran_no_instrument_failure":0,"n_unverified":1,"ran_from_kinds":[]}}},{"url":"/paper/improving-adversarial-transferability-with","slug":"improving-adversarial-transferability-with","title":"Improving Adversarial Transferability with Gradient Refining","date":"2021-05-11","arxiv_id":"2105.04834","repositories_listed":1,"syntology":null},{"url":"/paper/adv-makeup-a-new-imperceptible-and","slug":"adv-makeup-a-new-imperceptible-and","title":"Adv-Makeup: A New Imperceptible and Transferable Attack on Face Recognition","date":"2021-05-07","arxiv_id":"2105.03162","repositories_listed":1,"syntology":null},{"url":"/paper/attack-agnostic-adversarial-detection-on","slug":"attack-agnostic-adversarial-detection-on","title":"Attack-agnostic Adversarial Detection on Medical Data Using Explainable Machine Learning","date":"2021-05-05","arxiv_id":"2105.01959","repositories_listed":1,"syntology":null},{"url":"/paper/3d-adversarial-attacks-beyond-point-cloud","slug":"3d-adversarial-attacks-beyond-point-cloud","title":"3D Adversarial Attacks Beyond Point Cloud","date":"2021-04-25","arxiv_id":"2104.12146","repositories_listed":1,"syntology":{"n":1,"n_ran":1,"n_constructed":0,"n_ran_checked":0,"n_instrument":1,"n_unverified":0,"n_honours":0,"n_violates":0,"n_no_contract":0,"n_pointer_only":0,"phrase":"1 ran (of which 0 constructed an object rather than computing a result; 0 with no instrument failure: 0 honoured, 0 violated, 0 with no contract checked; 1 where Syntology's instrument failed) · 0 unverified","sample_list":"/paper/3d-adversarial-attacks-beyond-point-cloud#ran","syntology_url":"https://syntology.ai/paper/2104.12146","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2104.12146"}},"official":{"repos":["cuge1995/Mesh-Attack"],"state":"official (archive's flag): 1 ran","n_ran":1,"n_constructed":0,"n_ran_no_instrument_failure":0,"n_unverified":0,"ran_from_kinds":["official"]}}},{"url":"/paper/learning-transferable-3d-adversarial-cloaks","slug":"learning-transferable-3d-adversarial-cloaks","title":"Learning Transferable 3D Adversarial Cloaks for Deep Trained Detectors","date":"2021-04-22","arxiv_id":"2104.11101","repositories_listed":1,"syntology":null},{"url":"/paper/towards-adversarial-patch-analysis-and","slug":"towards-adversarial-patch-analysis-and","title":"Towards Adversarial Patch Analysis and Certified Defense against Crowd Counting","date":"2021-04-22","arxiv_id":"2104.10868","repositories_listed":1,"syntology":null},{"url":"/paper/adversarial-diffusion-attacks-on-graph-based","slug":"adversarial-diffusion-attacks-on-graph-based","title":"Adversarial Diffusion Attacks on Graph-based Traffic Prediction Models","date":"2021-04-19","arxiv_id":"2104.09369","repositories_listed":1,"syntology":null},{"url":"/paper/attacking-text-classifiers-via-sentence","slug":"attacking-text-classifiers-via-sentence","title":"R&R: Metric-guided Adversarial Sentence Generation","date":"2021-04-17","arxiv_id":"2104.08453","repositories_listed":1,"syntology":{"n":6,"n_ran":6,"n_constructed":0,"n_ran_checked":6,"n_instrument":0,"n_unverified":0,"n_honours":0,"n_violates":0,"n_no_contract":6,"n_pointer_only":0,"phrase":"6 ran (of which 0 constructed an object rather than computing a result; 6 with no instrument failure: 0 honoured, 0 violated, 6 with no contract checked; 0 where Syntology's instrument failed) · 0 unverified","sample_list":"/paper/attacking-text-classifiers-via-sentence#ran","syntology_url":"https://syntology.ai/paper/2104.08453","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2104.08453"}},"official":{"repos":["DAI-Lab/fibber"],"state":"official (archive's flag): 6 ran","n_ran":6,"n_constructed":0,"n_ran_no_instrument_failure":6,"n_unverified":0,"ran_from_kinds":["official"]}}},{"url":"/paper/fashion-guided-adversarial-attack-on-person","slug":"fashion-guided-adversarial-attack-on-person","title":"Fashion-Guided Adversarial Attack on Person Segmentation","date":"2021-04-17","arxiv_id":"2104.08422","repositories_listed":1,"syntology":null},{"url":"/paper/statistical-inference-for-individual-fairness-1","slug":"statistical-inference-for-individual-fairness-1","title":"Statistical inference for individual fairness","date":"2021-03-30","arxiv_id":"2103.16714","repositories_listed":1,"syntology":null},{"url":"/paper/robust-reinforcement-learning-under-model","slug":"robust-reinforcement-learning-under-model","title":"Robust Reinforcement Learning under model misspecification","date":"2021-03-29","arxiv_id":"2103.15370","repositories_listed":1,"syntology":null},{"url":"/paper/iou-attack-towards-temporally-coherent-black","slug":"iou-attack-towards-temporally-coherent-black","title":"IoU Attack: Towards Temporally Coherent Black-Box Adversarial Attack for Visual Object Tracking","date":"2021-03-27","arxiv_id":"2103.14938","repositories_listed":1,"syntology":{"n":1,"n_ran":1,"n_constructed":0,"n_ran_checked":1,"n_instrument":0,"n_unverified":0,"n_honours":0,"n_violates":1,"n_no_contract":0,"n_pointer_only":0,"phrase":"1 ran (of which 0 constructed an object rather than computing a result; 1 with no instrument failure: 0 honoured, 1 violated, 0 with no contract checked; 0 where Syntology's instrument failed) · 0 unverified","sample_list":"/paper/iou-attack-towards-temporally-coherent-black#ran","syntology_url":"https://syntology.ai/paper/2103.14938","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2103.14938"}},"official":{"repos":["VISION-SJTU/IoUattack"],"state":"official (archive's flag): 1 ran","n_ran":1,"n_constructed":0,"n_ran_no_instrument_failure":1,"n_unverified":0,"ran_from_kinds":["official"]}}},{"url":"/paper/textflint-unified-multilingual-robustness","slug":"textflint-unified-multilingual-robustness","title":"TextFlint: Unified Multilingual Robustness Evaluation Toolkit for Natural Language Processing","date":"2021-03-21","arxiv_id":"2103.11441","repositories_listed":1,"syntology":null},{"url":"/paper/boosting-adversarial-transferability-through","slug":"boosting-adversarial-transferability-through","title":"Boosting Adversarial Transferability through Enhanced Momentum","date":"2021-03-19","arxiv_id":"2103.10609","repositories_listed":1,"syntology":null},{"url":"/paper/sok-a-modularized-approach-to-study-the","slug":"sok-a-modularized-approach-to-study-the","title":"SoK: A Modularized Approach to Study the Security of Automatic Speech Recognition Systems","date":"2021-03-19","arxiv_id":"2103.10651","repositories_listed":1,"syntology":null},{"url":"/paper/anti-adversarially-manipulated-attributions","slug":"anti-adversarially-manipulated-attributions","title":"Anti-Adversarially Manipulated Attributions for Weakly and Semi-Supervised Semantic Segmentation","date":"2021-03-16","arxiv_id":"2103.08896","repositories_listed":1,"syntology":{"n":3,"n_ran":1,"n_constructed":0,"n_ran_checked":0,"n_instrument":1,"n_unverified":2,"n_honours":0,"n_violates":0,"n_no_contract":0,"n_pointer_only":0,"phrase":"1 ran (of which 0 constructed an object rather than computing a result; 0 with no instrument failure: 0 honoured, 0 violated, 0 with no contract checked; 1 where Syntology's instrument failed) · 2 unverified","sample_list":"/paper/anti-adversarially-manipulated-attributions#ran","syntology_url":"https://syntology.ai/paper/2103.08896","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2103.08896"}},"official":{"repos":["jbeomlee93/AdvCAM"],"state":"official (archive's flag): 1 ran","n_ran":1,"n_constructed":0,"n_ran_no_instrument_failure":0,"n_unverified":2,"ran_from_kinds":["official"]}}},{"url":"/paper/adversarial-laser-beam-effective-physical","slug":"adversarial-laser-beam-effective-physical","title":"Adversarial Laser Beam: Effective Physical-World Attack to DNNs in a Blink","date":"2021-03-11","arxiv_id":"2103.06504","repositories_listed":1,"syntology":{"n":2,"n_ran":2,"n_constructed":0,"n_ran_checked":2,"n_instrument":0,"n_unverified":0,"n_honours":2,"n_violates":0,"n_no_contract":0,"n_pointer_only":0,"phrase":"2 ran (of which 0 constructed an object rather than computing a result; 2 with no instrument failure: 2 honoured, 0 violated, 0 with no contract checked; 0 where Syntology's instrument failed) · 0 unverified","sample_list":"/paper/adversarial-laser-beam-effective-physical#ran","syntology_url":"https://syntology.ai/paper/2103.06504","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2103.06504"}},"official":{"repos":["RjDuan/Advlight"],"state":"official (archive's flag): 2 ran","n_ran":2,"n_constructed":0,"n_ran_no_instrument_failure":2,"n_unverified":0,"ran_from_kinds":["official"]}}},{"url":"/paper/basar-black-box-attack-on-skeletal-action","slug":"basar-black-box-attack-on-skeletal-action","title":"BASAR:Black-box Attack on Skeletal Action Recognition","date":"2021-03-09","arxiv_id":"2103.05266","repositories_listed":1,"syntology":null},{"url":"/paper/stabilized-medical-image-attacks","slug":"stabilized-medical-image-attacks","title":"Stabilized Medical Image Attacks","date":"2021-03-09","arxiv_id":"2103.05232","repositories_listed":1,"syntology":{"n":5,"n_ran":4,"n_constructed":1,"n_ran_checked":2,"n_instrument":2,"n_unverified":1,"n_honours":1,"n_violates":0,"n_no_contract":1,"n_pointer_only":5,"phrase":"4 ran (of which 1 constructed an object rather than computing a result; 2 with no instrument failure: 1 honoured, 0 violated, 1 with no contract checked; 2 where Syntology's instrument failed) · 1 unverified","sample_list":"/paper/stabilized-medical-image-attacks#ran","syntology_url":"https://syntology.ai/paper/2103.05232","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2103.05232"}},"official":{"repos":["imogenqi/SMA"],"state":"official (archive's flag): 4 ran","n_ran":4,"n_constructed":1,"n_ran_no_instrument_failure":2,"n_unverified":1,"ran_from_kinds":["official"]}}},{"url":"/paper/understanding-the-robustness-of-skeleton","slug":"understanding-the-robustness-of-skeleton","title":"Understanding the Robustness of Skeleton-based Action Recognition under Adversarial Attack","date":"2021-03-09","arxiv_id":"2103.05347","repositories_listed":1,"syntology":{"n":6,"n_ran":2,"n_constructed":2,"n_ran_checked":2,"n_instrument":0,"n_unverified":4,"n_honours":0,"n_violates":0,"n_no_contract":2,"n_pointer_only":6,"phrase":"2 ran (of which 2 constructed an object rather than computing a result; 2 with no instrument failure: 0 honoured, 0 violated, 2 with no contract checked; 0 where Syntology's instrument failed) · 4 unverified; every one of the 2 samples that ran constructed an object rather than computing a result","sample_list":"/paper/understanding-the-robustness-of-skeleton#ran","syntology_url":"https://syntology.ai/paper/2103.05347","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2103.05347"}},"official":{"repos":["realcrane/SMART"],"state":"official (archive's flag): 2 ran","n_ran":2,"n_constructed":2,"n_ran_no_instrument_failure":2,"n_unverified":4,"ran_from_kinds":["official"]}}},{"url":"/paper/towards-evaluating-the-robustness-of-deep","slug":"towards-evaluating-the-robustness-of-deep","title":"Towards Evaluating the Robustness of Deep Diagnostic Models by Adversarial Attack","date":"2021-03-05","arxiv_id":"2103.03438","repositories_listed":1,"syntology":null},{"url":"/paper/a-survey-on-universal-adversarial-attack","slug":"a-survey-on-universal-adversarial-attack","title":"A Survey On Universal Adversarial Attack","date":"2021-03-02","arxiv_id":"2103.01498","repositories_listed":1,"syntology":null},{"url":"/paper/online-adversarial-attacks","slug":"online-adversarial-attacks","title":"Online Adversarial Attacks","date":"2021-03-02","arxiv_id":"2103.02014","repositories_listed":1,"syntology":{"n":3,"n_ran":1,"n_constructed":0,"n_ran_checked":1,"n_instrument":0,"n_unverified":2,"n_honours":0,"n_violates":0,"n_no_contract":1,"n_pointer_only":0,"phrase":"1 ran (of which 0 constructed an object rather than computing a result; 1 with no instrument failure: 0 honoured, 0 violated, 1 with no contract checked; 0 where Syntology's instrument failed) · 2 unverified","sample_list":"/paper/online-adversarial-attacks#ran","syntology_url":"https://syntology.ai/paper/2103.02014","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2103.02014"}},"official":{"repos":["facebookresearch/OnlineAttacks"],"state":"official (archive's flag): 1 ran","n_ran":1,"n_constructed":0,"n_ran_no_instrument_failure":1,"n_unverified":2,"ran_from_kinds":["official"]}}},{"url":"/paper/model-agnostic-defense-for-lane-detection","slug":"model-agnostic-defense-for-lane-detection","title":"Model-Agnostic Defense for Lane Detection against Adversarial Attack","date":"2021-03-01","arxiv_id":"2103.00663","repositories_listed":1,"syntology":null},{"url":"/paper/on-fast-adversarial-robustness-adaptation-in-1","slug":"on-fast-adversarial-robustness-adaptation-in-1","title":"On Fast Adversarial Robustness Adaptation in Model-Agnostic Meta-Learning","date":"2021-02-20","arxiv_id":"2102.10454","repositories_listed":1,"syntology":null},{"url":"/paper/adversarial-attack-on-network-embeddings-via","slug":"adversarial-attack-on-network-embeddings-via","title":"Adversarial Attack on Network Embeddings via Supervised Network Poisoning","date":"2021-02-14","arxiv_id":"2102.07164","repositories_listed":1,"syntology":null},{"url":"/paper/enhancing-real-world-adversarial-patches-with","slug":"enhancing-real-world-adversarial-patches-with","title":"Enhancing Real-World Adversarial Patches through 3D Modeling of Complex Target Scenes","date":"2021-02-10","arxiv_id":"2102.05334","repositories_listed":1,"syntology":null},{"url":"/paper/robic-a-benchmark-suite-for-assessing","slug":"robic-a-benchmark-suite-for-assessing","title":"RoBIC: A benchmark suite for assessing classifiers robustness","date":"2021-02-10","arxiv_id":"2102.05368","repositories_listed":1,"syntology":null},{"url":"/paper/introducing-and-assessing-the-explainable-ai","slug":"introducing-and-assessing-the-explainable-ai","title":"Visual explanation of black-box model: Similarity Difference and Uniqueness (SIDU) method","date":"2021-01-26","arxiv_id":"2101.10710","repositories_listed":1,"syntology":null},{"url":"/paper/probabilistic-robustness-analysis-for-dnns","slug":"probabilistic-robustness-analysis-for-dnns","title":"Towards Practical Robustness Analysis for DNNs based on PAC-Model Learning","date":"2021-01-25","arxiv_id":"2101.10102","repositories_listed":1,"syntology":null},{"url":"/paper/random-transformation-of-image-brightness-for","slug":"random-transformation-of-image-brightness-for","title":"Random Transformation of Image Brightness for Adversarial Attack","date":"2021-01-12","arxiv_id":"2101.04321","repositories_listed":1,"syntology":null},{"url":"/paper/robustness-of-on-device-models-adversarial","slug":"robustness-of-on-device-models-adversarial","title":"Robustness of on-device Models: Adversarial Attack to Deep Learning Models on Android Apps","date":"2021-01-12","arxiv_id":"2101.04401","repositories_listed":1,"syntology":null},{"url":"/paper/patch-wise-perturbation-for-adversarial","slug":"patch-wise-perturbation-for-adversarial","title":"Patch-wise++ Perturbation for Adversarial Targeted Attacks","date":"2020-12-31","arxiv_id":"2012.15503","repositories_listed":1,"syntology":null},{"url":"/paper/sparse-adversarial-attack-to-object-detection","slug":"sparse-adversarial-attack-to-object-detection","title":"Sparse Adversarial Attack to Object Detection","date":"2020-12-26","arxiv_id":"2012.13692","repositories_listed":1,"syntology":null},{"url":"/paper/efficient-training-of-robust-decision-trees","slug":"efficient-training-of-robust-decision-trees","title":"Efficient Training of Robust Decision Trees Against Adversarial Examples","date":"2020-12-18","arxiv_id":"2012.10438","repositories_listed":1,"syntology":{"n":1,"n_ran":1,"n_constructed":0,"n_ran_checked":1,"n_instrument":0,"n_unverified":0,"n_honours":1,"n_violates":0,"n_no_contract":0,"n_pointer_only":0,"phrase":"1 ran (of which 0 constructed an object rather than computing a result; 1 with no instrument failure: 1 honoured, 0 violated, 0 with no contract checked; 0 where Syntology's instrument failed) · 0 unverified","sample_list":"/paper/efficient-training-of-robust-decision-trees#ran","syntology_url":"https://syntology.ai/paper/2012.10438","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2012.10438"}},"official":{"repos":["tudelft-cda-lab/GROOT"],"state":"official (archive's flag): 1 ran","n_ran":1,"n_constructed":0,"n_ran_no_instrument_failure":1,"n_unverified":0,"ran_from_kinds":["official"]}}},{"url":"/paper/a-hierarchical-feature-constraint-to","slug":"a-hierarchical-feature-constraint-to","title":"A Hierarchical Feature Constraint to Camouflage Medical Adversarial Attacks","date":"2020-12-17","arxiv_id":"2012.09501","repositories_listed":1,"syntology":null},{"url":"/paper/exacerbating-algorithmic-bias-through","slug":"exacerbating-algorithmic-bias-through","title":"Exacerbating Algorithmic Bias through Fairness Attacks","date":"2020-12-16","arxiv_id":"2012.08723","repositories_listed":1,"syntology":{"n":3,"n_ran":3,"n_constructed":0,"n_ran_checked":0,"n_instrument":3,"n_unverified":0,"n_honours":0,"n_violates":0,"n_no_contract":0,"n_pointer_only":0,"phrase":"3 ran (of which 0 constructed an object rather than computing a result; 0 with no instrument failure: 0 honoured, 0 violated, 0 with no contract checked; 3 where Syntology's instrument failed) · 0 unverified","sample_list":"/paper/exacerbating-algorithmic-bias-through#ran","syntology_url":"https://syntology.ai/paper/2012.08723","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2012.08723"}},"official":{"repos":["Ninarehm/attack"],"state":"official (archive's flag): 3 ran","n_ran":3,"n_constructed":0,"n_ran_no_instrument_failure":0,"n_unverified":0,"ran_from_kinds":["official"]}}},{"url":"/paper/a-distributed-black-box-adversarial-attack","slug":"a-distributed-black-box-adversarial-attack","title":"A Distributed Black-Box Adversarial Attack Based on Multi-Group Particle Swarm Optimization","date":"2020-12-14","arxiv_id":null,"repositories_listed":1,"syntology":null},{"url":"/paper/disentangled-information-bottleneck","slug":"disentangled-information-bottleneck","title":"Disentangled Information Bottleneck","date":"2020-12-14","arxiv_id":"2012.07372","repositories_listed":1,"syntology":null},{"url":"/paper/composite-adversarial-attacks","slug":"composite-adversarial-attacks","title":"Composite Adversarial Attacks","date":"2020-12-10","arxiv_id":"2012.05434","repositories_listed":1,"syntology":{"n":3,"n_ran":3,"n_constructed":0,"n_ran_checked":1,"n_instrument":2,"n_unverified":0,"n_honours":0,"n_violates":1,"n_no_contract":0,"n_pointer_only":0,"phrase":"3 ran (of which 0 constructed an object rather than computing a result; 1 with no instrument failure: 0 honoured, 1 violated, 0 with no contract checked; 2 where Syntology's instrument failed) · 0 unverified","sample_list":"/paper/composite-adversarial-attacks#ran","syntology_url":"https://syntology.ai/paper/2012.05434","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2012.05434"}},"official":{"repos":["vtddggg/CAA"],"state":"official (archive's flag): 3 ran","n_ran":3,"n_constructed":0,"n_ran_no_instrument_failure":1,"n_unverified":0,"ran_from_kinds":["official"]}}},{"url":"/paper/geometric-adversarial-attacks-and-defenses-on","slug":"geometric-adversarial-attacks-and-defenses-on","title":"Geometric Adversarial Attacks and Defenses on 3D Point Clouds","date":"2020-12-10","arxiv_id":"2012.05657","repositories_listed":1,"syntology":null},{"url":"/paper/spaa-stealthy-projector-based-adversarial","slug":"spaa-stealthy-projector-based-adversarial","title":"SPAA: Stealthy Projector-based Adversarial Attacks on Deep Image Classifiers","date":"2020-12-10","arxiv_id":"2012.05858","repositories_listed":1,"syntology":null},{"url":"/paper/using-feature-alignment-can-improve-clean","slug":"using-feature-alignment-can-improve-clean","title":"Using Feature Alignment Can Improve Clean Average Precision and Adversarial Robustness in Object Detection","date":"2020-12-08","arxiv_id":"2012.04382","repositories_listed":1,"syntology":null},{"url":"/paper/fencebox-a-platform-for-defeating-adversarial","slug":"fencebox-a-platform-for-defeating-adversarial","title":"FenceBox: A Platform for Defeating Adversarial Examples with Data Augmentation Techniques","date":"2020-12-03","arxiv_id":"2012.01701","repositories_listed":1,"syntology":null},{"url":"/paper/adversarial-learning-for-robust-deep","slug":"adversarial-learning-for-robust-deep","title":"Adversarial Learning for Robust Deep Clustering","date":"2020-12-01","arxiv_id":null,"repositories_listed":1,"syntology":null},{"url":"/paper/enhancing-neural-models-with-vulnerability","slug":"enhancing-neural-models-with-vulnerability","title":"Enhancing Neural Models with Vulnerability via Adversarial Attack","date":"2020-12-01","arxiv_id":null,"repositories_listed":1,"syntology":null},{"url":"/paper/guided-adversarial-attack-for-evaluating-and-1","slug":"guided-adversarial-attack-for-evaluating-and-1","title":"Guided Adversarial Attack for Evaluating and Enhancing Adversarial Defenses","date":"2020-11-30","arxiv_id":"2011.14969","repositories_listed":1,"syntology":null},{"url":"/paper/a-targeted-universal-attack-on-graph","slug":"a-targeted-universal-attack-on-graph","title":"A Targeted Universal Attack on Graph Convolutional Network","date":"2020-11-29","arxiv_id":"2011.14365","repositories_listed":1,"syntology":null},{"url":"/paper/surfree-a-fast-surrogate-free-black-box","slug":"surfree-a-fast-surrogate-free-black-box","title":"SurFree: a fast surrogate-free black-box attack","date":"2020-11-25","arxiv_id":"2011.12807","repositories_listed":1,"syntology":{"n":1,"n_ran":1,"n_constructed":0,"n_ran_checked":1,"n_instrument":0,"n_unverified":0,"n_honours":1,"n_violates":0,"n_no_contract":0,"n_pointer_only":1,"phrase":"1 ran (of which 0 constructed an object rather than computing a result; 1 with no instrument failure: 1 honoured, 0 violated, 0 with no contract checked; 0 where Syntology's instrument failed) · 0 unverified","sample_list":"/paper/surfree-a-fast-surrogate-free-black-box#ran","syntology_url":"https://syntology.ai/paper/2011.12807","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2011.12807"}},"official":{"repos":["t-maho/SurFree"],"state":"official (archive's flag): 1 ran","n_ran":1,"n_constructed":0,"n_ran_no_instrument_failure":1,"n_unverified":0,"ran_from_kinds":["official"]}}},{"url":"/paper/combining-gans-and-autoencoders-for-efficient","slug":"combining-gans-and-autoencoders-for-efficient","title":"Combining GANs and AutoEncoders for Efficient Anomaly Detection","date":"2020-11-16","arxiv_id":"2011.08102","repositories_listed":1,"syntology":null},{"url":"/paper/efficient-and-transferable-adversarial","slug":"efficient-and-transferable-adversarial","title":"Efficient and Transferable Adversarial Examples from Bayesian Neural Networks","date":"2020-11-10","arxiv_id":"2011.05074","repositories_listed":1,"syntology":{"n":2,"n_ran":2,"n_constructed":0,"n_ran_checked":0,"n_instrument":2,"n_unverified":0,"n_honours":0,"n_violates":0,"n_no_contract":0,"n_pointer_only":2,"phrase":"2 ran (of which 0 constructed an object rather than computing a result; 0 with no instrument failure: 0 honoured, 0 violated, 0 with no contract checked; 2 where Syntology's instrument failed) · 0 unverified","sample_list":"/paper/efficient-and-transferable-adversarial#ran","syntology_url":"https://syntology.ai/paper/2011.05074","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2011.05074"}},"official":{"repos":["framartin/transferable-bnn-adv-ex"],"state":"official (archive's flag): 2 ran","n_ran":2,"n_constructed":0,"n_ran_no_instrument_failure":0,"n_unverified":0,"ran_from_kinds":["official"]}}},{"url":"/paper/bridging-the-performance-gap-between-fgsm-and","slug":"bridging-the-performance-gap-between-fgsm-and","title":"Bridging the Performance Gap between FGSM and PGD Adversarial Training","date":"2020-11-07","arxiv_id":"2011.05157","repositories_listed":1,"syntology":null},{"url":"/paper/single-node-attack-for-fooling-graph-neural-1","slug":"single-node-attack-for-fooling-graph-neural-1","title":"Single-Node Attacks for Fooling Graph Neural Networks","date":"2020-11-06","arxiv_id":"2011.03574","repositories_listed":1,"syntology":null},{"url":"/paper/deep-dup-an-adversarial-weight-duplication","slug":"deep-dup-an-adversarial-weight-duplication","title":"Deep-Dup: An Adversarial Weight Duplication Attack Framework to Crush Deep Neural Network in Multi-Tenant FPGA","date":"2020-11-05","arxiv_id":"2011.03006","repositories_listed":1,"syntology":null},{"url":"/paper/defense-friendly-images-in-adversarial","slug":"defense-friendly-images-in-adversarial","title":"Defense-friendly Images in Adversarial Attacks: Dataset and Metrics for Perturbation Difficulty","date":"2020-11-05","arxiv_id":"2011.02675","repositories_listed":1,"syntology":null},{"url":"/paper/detecting-word-sense-disambiguation-biases-in","slug":"detecting-word-sense-disambiguation-biases-in","title":"Detecting Word Sense Disambiguation Biases in Machine Translation for Model-Agnostic Adversarial Attacks","date":"2020-11-03","arxiv_id":"2011.01846","repositories_listed":1,"syntology":null},{"url":"/paper/perception-matters-exploring-imperceptible","slug":"perception-matters-exploring-imperceptible","title":"Perception Matters: Exploring Imperceptible and Transferable Anti-forensics for GAN-generated Fake Face Imagery Detection","date":"2020-10-29","arxiv_id":"2010.15886","repositories_listed":1,"syntology":null},{"url":"/paper/object-hider-adversarial-patch-attack-against","slug":"object-hider-adversarial-patch-attack-against","title":"Object Hider: Adversarial Patch Attack Against Object Detectors","date":"2020-10-28","arxiv_id":"2010.14974","repositories_listed":1,"syntology":null}],"record_sha256":"e5e828d1b4681a0c9d7f78f8d370acf7b755ca12c7454e42dae086c91d02ca33","record_changed_at":"2026-09-28","record_changed_at_basis":"first_hashed"}