{"about":{"non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","site":"https://codewithpapers.app","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page","syntology":{"site":"https://syntology.ai","developers":"https://syntology.ai/developers","mcp":{"server":"https://syntology.ai/mcp","transport":"streamable-http","server_card":"https://syntology.ai/.well-known/mcp/server-card.json","auth":{"type":"trial token, no account","trial_token":"https://syntology.ai/api/oauth/trial/token","method":"POST","docs":"https://syntology.ai/developers"}},"have":"https://syntology.ai/api/graph/have?x=<method, arXiv id or title> (free, answers coverage only)","paper_base":"https://syntology.ai/paper/","atlas_base":"https://app.syntology.ai/?focus="},"machine_readable":[{"url":"https://codewithpapers.app/llms.txt","what":"the machine catalog: every machine-readable file, counted"},{"url":"https://codewithpapers.app/index/manifest.json","what":"paper-to-code index by arXiv id, with Syntology's counts"},{"url":"https://codewithpapers.app/search/manifest.json","what":"site search index (titles, authors) and its files"},{"url":"https://codewithpapers.app/download","what":"bulk files: Syntology's layer, described there"},{"url":"https://codewithpapers.app/build_manifest.json","what":"the build record: inputs, counts, exclusions, probes"}]},"url":"/task/adversarial-attack/papers/8","list_of":"/task/adversarial-attack","task":"Adversarial Attack","archive":{"snapshot":"2025-07-28"},"key_notes":{"n_ran_checked":"legacy name, kept unchanged so existing readers do not break: it counts the samples that ran with no instrument failure (honoured, violated, and ran with no contract checked); it does not mean a contract was checked, and the pages print it as 'K with no instrument failure', not 'K checked'","n_constructed":"a sub-count of the samples that ran, never subtracted from them and never a failure: an executed sample whose run returned an instance of its own class (fixture_out_type equals the entry name): the run built an object and did not compute a result (Syntology's RAN record, counts.constructed)"},"syntology_read_at":"2026-09-28T10:30:06+00:00","order":"archive","order_definition":"repositories listed in the archive (most first), then date (newest first), then slug","page":8,"pages_in_order":19,"rows_per_page":100,"rows":[701,800],"of":1808,"counts":{"archive_papers_tagged":1808,"with_a_code_link":745,"where_syntology_ran_a_sample":206,"not_listed_spam_title":0,"listed":1808,"listed_where_code_ran":206,"where_syntology_ran_a_sample_split":{"with_a_run_with_no_instrument_failure":161,"every_run_a_failure_of_syntologys_instrument":45,"listed_with_a_run_with_no_instrument_failure":161,"listed_every_run_a_failure_of_syntologys_instrument":45,"filter":{"states":["a run with no instrument failure","any run, instrument failures included"],"default":"a run with no instrument failure","note":"on the 'only where code ran' pages the default hides, in the browser, the rows where every run was a failure of Syntology's instrument; the second state shows them again. Rows are hidden, never re-ordered; these twins list every row"}},"definition":"distinct papers the archive tags; 'where Syntology ran a sample' counts papers with at least one harvested sample that ran, which is not a correctness claim"},"first_page":"/task/adversarial-attack","prev":"/task/adversarial-attack/papers/7","next":"/task/adversarial-attack/papers/9","papers":[{"url":"/paper/real-time-adversarial-attacks","slug":"real-time-adversarial-attacks","title":"Real-Time Adversarial Attacks","date":"2019-05-31","arxiv_id":"1905.13399","repositories_listed":1,"syntology":null},{"url":"/paper/reverse-kl-divergence-training-of-prior","slug":"reverse-kl-divergence-training-of-prior","title":"Reverse KL-Divergence Training of Prior Networks: Improved Uncertainty and Adversarial Robustness","date":"2019-05-31","arxiv_id":"1905.13472","repositories_listed":1,"syntology":null},{"url":"/paper/190600001","slug":"190600001","title":"Functional Adversarial Attacks","date":"2019-05-29","arxiv_id":"1906.00001","repositories_listed":1,"syntology":{"n":4,"n_ran":4,"n_constructed":0,"n_ran_checked":3,"n_instrument":1,"n_unverified":0,"n_honours":0,"n_violates":0,"n_no_contract":3,"n_pointer_only":1,"phrase":"4 ran (of which 0 constructed an object rather than computing a result; 3 with no instrument failure: 0 honoured, 0 violated, 3 with no contract checked; 1 where Syntology's instrument failed) · 0 unverified","sample_list":"/paper/190600001#ran","syntology_url":"https://syntology.ai/paper/1906.00001","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1906.00001"}},"official":{"repos":["cassidylaidlaw/ReColorAdv"],"state":"official (archive's flag): 4 ran","n_ran":4,"n_constructed":0,"n_ran_no_instrument_failure":3,"n_unverified":0,"ran_from_kinds":["official"]}}},{"url":"/paper/accelerating-monte-carlo-bayesian-inference","slug":"accelerating-monte-carlo-bayesian-inference","title":"Accelerating Monte Carlo Bayesian Inference via Approximating Predictive Uncertainty over Simplex","date":"2019-05-29","arxiv_id":"1905.12194","repositories_listed":1,"syntology":null},{"url":"/paper/190513545","slug":"190513545","title":"High Frequency Component Helps Explain the Generalization of Convolutional Neural Networks","date":"2019-05-28","arxiv_id":"1905.13545","repositories_listed":1,"syntology":{"n":3,"n_ran":3,"n_constructed":0,"n_ran_checked":1,"n_instrument":2,"n_unverified":0,"n_honours":0,"n_violates":1,"n_no_contract":0,"n_pointer_only":3,"phrase":"3 ran (of which 0 constructed an object rather than computing a result; 1 with no instrument failure: 0 honoured, 1 violated, 0 with no contract checked; 2 where Syntology's instrument failed) · 0 unverified","sample_list":"/paper/190513545#ran","syntology_url":"https://syntology.ai/paper/1905.13545","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1905.13545"}},"official":{"repos":["HaohanWang/HFC"],"state":"official (archive's flag): 3 ran","n_ran":3,"n_constructed":0,"n_ran_no_instrument_failure":1,"n_unverified":0,"ran_from_kinds":["official"]}}},{"url":"/paper/fooling-detection-alone-is-not-enough-first","slug":"fooling-detection-alone-is-not-enough-first","title":"Fooling Detection Alone is Not Enough: First Adversarial Attack against Multiple Object Tracking","date":"2019-05-27","arxiv_id":"1905.11026","repositories_listed":1,"syntology":null},{"url":"/paper/scaleable-input-gradient-regularization-for","slug":"scaleable-input-gradient-regularization-for","title":"Scaleable input gradient regularization for adversarial robustness","date":"2019-05-27","arxiv_id":"1905.11468","repositories_listed":1,"syntology":{"n":11,"n_ran":9,"n_constructed":0,"n_ran_checked":8,"n_instrument":1,"n_unverified":2,"n_honours":0,"n_violates":0,"n_no_contract":8,"n_pointer_only":1,"phrase":"9 ran (of which 0 constructed an object rather than computing a result; 8 with no instrument failure: 0 honoured, 0 violated, 8 with no contract checked; 1 where Syntology's instrument failed) · 2 unverified","sample_list":"/paper/scaleable-input-gradient-regularization-for#ran","syntology_url":"https://syntology.ai/paper/1905.11468","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1905.11468"}},"official":{"repos":["cfinlay/tulip"],"state":"official (archive's flag): 9 ran","n_ran":9,"n_constructed":0,"n_ran_no_instrument_failure":8,"n_unverified":2,"ran_from_kinds":["official"]}}},{"url":"/paper/things-you-may-not-know-about-adversarial","slug":"things-you-may-not-know-about-adversarial","title":"Taking Care of The Discretization Problem: A Comprehensive Study of the Discretization Problem and A Black-Box Adversarial Attack in Discrete Integer Domain","date":"2019-05-19","arxiv_id":"1905.07672","repositories_listed":1,"syntology":null},{"url":"/paper/harnessing-the-vulnerability-of-latent-layers","slug":"harnessing-the-vulnerability-of-latent-layers","title":"Harnessing the Vulnerability of Latent Layers in Adversarially Trained Models","date":"2019-05-13","arxiv_id":"1905.05186","repositories_listed":1,"syntology":null},{"url":"/paper/exact-adversarial-attack-to-image-captioning","slug":"exact-adversarial-attack-to-image-captioning","title":"Exact Adversarial Attack to Image Captioning via Structured Output Learning with Latent Variables","date":"2019-05-10","arxiv_id":"1905.04016","repositories_listed":1,"syntology":{"n":1,"n_ran":0,"n_constructed":0,"n_ran_checked":0,"n_instrument":0,"n_unverified":1,"n_honours":0,"n_violates":0,"n_no_contract":0,"n_pointer_only":1,"phrase":"0 ran · 1 unverified","sample_list":"/paper/exact-adversarial-attack-to-image-captioning#ran","syntology_url":"https://syntology.ai/paper/1905.04016","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1905.04016"}},"official":null}},{"url":"/paper/camou-learning-physical-vehicle-camouflages","slug":"camou-learning-physical-vehicle-camouflages","title":"CAMOU: Learning Physical Vehicle Camouflages to Adversarially Attack Detectors in the Wild","date":"2019-05-01","arxiv_id":null,"repositories_listed":1,"syntology":null},{"url":"/paper/nattack-learning-the-distributions-of","slug":"nattack-learning-the-distributions-of","title":"NATTACK: Learning the Distributions of Adversarial Examples for an Improved Black-Box Attack on Deep Neural Networks","date":"2019-05-01","arxiv_id":"1905.00441","repositories_listed":1,"syntology":null},{"url":"/paper/gotta-catch-em-all-using-concealed-trapdoors","slug":"gotta-catch-em-all-using-concealed-trapdoors","title":"Gotta Catch 'Em All: Using Honeypots to Catch Adversarial Attacks on Neural Networks","date":"2019-04-18","arxiv_id":"1904.08554","repositories_listed":1,"syntology":null},{"url":"/paper/towards-analyzing-semantic-robustness-of-deep","slug":"towards-analyzing-semantic-robustness-of-deep","title":"Towards Analyzing Semantic Robustness of Deep Neural Networks","date":"2019-04-09","arxiv_id":"1904.04621","repositories_listed":1,"syntology":null},{"url":"/paper/curls-whey-boosting-black-box-adversarial","slug":"curls-whey-boosting-black-box-adversarial","title":"Curls & Whey: Boosting Black-Box Adversarial Attacks","date":"2019-04-02","arxiv_id":"1904.01160","repositories_listed":1,"syntology":{"n":6,"n_ran":5,"n_constructed":0,"n_ran_checked":4,"n_instrument":1,"n_unverified":1,"n_honours":0,"n_violates":1,"n_no_contract":3,"n_pointer_only":2,"phrase":"5 ran (of which 0 constructed an object rather than computing a result; 4 with no instrument failure: 0 honoured, 1 violated, 3 with no contract checked; 1 where Syntology's instrument failed) · 1 unverified","sample_list":"/paper/curls-whey-boosting-black-box-adversarial#ran","syntology_url":"https://syntology.ai/paper/1904.01160","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1904.01160"}},"official":{"repos":["walegahaha/Curls-Whey"],"state":"official (archive's flag): 5 ran","n_ran":5,"n_constructed":0,"n_ran_no_instrument_failure":4,"n_unverified":1,"ran_from_kinds":["official"]}}},{"url":"/paper/scaling-up-the-randomized-gradient-free","slug":"scaling-up-the-randomized-gradient-free","title":"Scaling up the randomized gradient-free adversarial attack reveals overestimation of robustness using established attacks","date":"2019-03-27","arxiv_id":"1903.11359","repositories_listed":1,"syntology":{"n":2,"n_ran":2,"n_constructed":0,"n_ran_checked":1,"n_instrument":1,"n_unverified":0,"n_honours":1,"n_violates":0,"n_no_contract":0,"n_pointer_only":2,"phrase":"2 ran (of which 0 constructed an object rather than computing a result; 1 with no instrument failure: 1 honoured, 0 violated, 0 with no contract checked; 1 where Syntology's instrument failed) · 0 unverified","sample_list":"/paper/scaling-up-the-randomized-gradient-free#ran","syntology_url":"https://syntology.ai/paper/1903.11359","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1903.11359"}},"official":{"repos":["jonasrauber/linear-region-attack"],"state":"official (archive's flag): 2 ran","n_ran":2,"n_constructed":0,"n_ran_no_instrument_failure":1,"n_unverified":0,"ran_from_kinds":["official"]}}},{"url":"/paper/text-processing-like-humans-do-visually","slug":"text-processing-like-humans-do-visually","title":"Text Processing Like Humans Do: Visually Attacking and Shielding NLP Systems","date":"2019-03-27","arxiv_id":"1903.11508","repositories_listed":1,"syntology":{"n":1,"n_ran":0,"n_constructed":0,"n_ran_checked":0,"n_instrument":0,"n_unverified":1,"n_honours":0,"n_violates":0,"n_no_contract":0,"n_pointer_only":0,"phrase":"0 ran · 1 unverified","sample_list":"/paper/text-processing-like-humans-do-visually#ran","syntology_url":"https://syntology.ai/paper/1903.11508","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1903.11508"}},"official":{"repos":["UKPLab/naacl2019-like-humans-visual-attacks"],"state":"official: harvested, nothing ran","n_ran":0,"n_constructed":0,"n_ran_no_instrument_failure":0,"n_unverified":1,"ran_from_kinds":[]}}},{"url":"/paper/defending-against-whitebox-adversarial","slug":"defending-against-whitebox-adversarial","title":"Defending against Whitebox Adversarial Attacks via Randomized Discretization","date":"2019-03-25","arxiv_id":"1903.10586","repositories_listed":1,"syntology":null},{"url":"/paper/the-logbarrier-adversarial-attack-making","slug":"the-logbarrier-adversarial-attack-making","title":"The LogBarrier adversarial attack: making effective use of decision boundary information","date":"2019-03-25","arxiv_id":"1903.10396","repositories_listed":1,"syntology":null},{"url":"/paper/adversarial-attacks-on-deep-neural-networks","slug":"adversarial-attacks-on-deep-neural-networks","title":"Adversarial Attacks on Deep Neural Networks for Time Series Classification","date":"2019-03-17","arxiv_id":"1903.07054","repositories_listed":1,"syntology":null},{"url":"/paper/out-domain-examples-for-generative-models","slug":"out-domain-examples-for-generative-models","title":"Adversarial Out-domain Examples for Generative Models","date":"2019-03-07","arxiv_id":"1903.02926","repositories_listed":1,"syntology":null},{"url":"/paper/is-ami-attacks-meet-interpretability-robust","slug":"is-ami-attacks-meet-interpretability-robust","title":"Is AmI (Attacks Meet Interpretability) Robust to Adversarial Examples?","date":"2019-02-06","arxiv_id":"1902.02322","repositories_listed":1,"syntology":null},{"url":"/paper/adversarial-metric-attack-for-person-re","slug":"adversarial-metric-attack-for-person-re","title":"Adversarial Metric Attack and Defense for Person Re-identification","date":"2019-01-30","arxiv_id":"1901.10650","repositories_listed":1,"syntology":null},{"url":"/paper/adversarial-attack-and-defense-on-graph-data","slug":"adversarial-attack-and-defense-on-graph-data","title":"Adversarial Attack and Defense on Graph Data: A Survey","date":"2018-12-26","arxiv_id":"1812.10528","repositories_listed":1,"syntology":null},{"url":"/paper/learning-transferable-adversarial-examples","slug":"learning-transferable-adversarial-examples","title":"Learning Transferable Adversarial Examples via Ghost Networks","date":"2018-12-09","arxiv_id":"1812.03413","repositories_listed":1,"syntology":null},{"url":"/paper/sada-semantic-adversarial-diagnostic-attacks","slug":"sada-semantic-adversarial-diagnostic-attacks","title":"SADA: Semantic Adversarial Diagnostic Attacks for Autonomous Applications","date":"2018-12-05","arxiv_id":"1812.02132","repositories_listed":1,"syntology":null},{"url":"/paper/distorting-neural-representations-to-generate","slug":"distorting-neural-representations-to-generate","title":"Task-generalizable Adversarial Attack based on Perceptual Metric","date":"2018-11-22","arxiv_id":"1811.09020","repositories_listed":1,"syntology":null},{"url":"/paper/parametric-noise-injection-trainable","slug":"parametric-noise-injection-trainable","title":"Parametric Noise Injection: Trainable Randomness to Improve Deep Neural Network Robustness against Adversarial Attack","date":"2018-11-22","arxiv_id":"1811.09310","repositories_listed":1,"syntology":{"n":8,"n_ran":6,"n_constructed":0,"n_ran_checked":6,"n_instrument":0,"n_unverified":2,"n_honours":0,"n_violates":0,"n_no_contract":6,"n_pointer_only":3,"phrase":"6 ran (of which 0 constructed an object rather than computing a result; 6 with no instrument failure: 0 honoured, 0 violated, 6 with no contract checked; 0 where Syntology's instrument failed) · 2 unverified","sample_list":"/paper/parametric-noise-injection-trainable#ran","syntology_url":"https://syntology.ai/paper/1811.09310","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1811.09310"}},"official":{"repos":["elliothe/CVPR_2019_PNI"],"state":"official (archive's flag): 6 ran","n_ran":6,"n_constructed":0,"n_ran_no_instrument_failure":6,"n_unverified":2,"ran_from_kinds":["official"]}}},{"url":"/paper/improved-network-robustness-with-adversary","slug":"improved-network-robustness-with-adversary","title":"Improved Network Robustness with Adversary Critic","date":"2018-10-30","arxiv_id":"1810.12576","repositories_listed":1,"syntology":null},{"url":"/paper/the-adversarial-attack-and-detection-under","slug":"the-adversarial-attack-and-detection-under","title":"The Adversarial Attack and Detection under the Fisher Information Metric","date":"2018-10-09","arxiv_id":"1810.03806","repositories_listed":1,"syntology":null},{"url":"/paper/caad-2018-generating-transferable-adversarial","slug":"caad-2018-generating-transferable-adversarial","title":"CAAD 2018: Generating Transferable Adversarial Examples","date":"2018-09-29","arxiv_id":"1810.01268","repositories_listed":1,"syntology":null},{"url":"/paper/adversarial-defense-via-data-dependent","slug":"adversarial-defense-via-data-dependent","title":"Adversarial Defense via Data Dependent Activation Function and Total Variation Minimization","date":"2018-09-23","arxiv_id":"1809.08516","repositories_listed":1,"syntology":null},{"url":"/paper/structured-adversarial-attack-towards-general","slug":"structured-adversarial-attack-towards-general","title":"Structured Adversarial Attack: Towards General Implementation and Better Interpretability","date":"2018-08-05","arxiv_id":"1808.01664","repositories_listed":1,"syntology":{"n":1,"n_ran":0,"n_constructed":0,"n_ran_checked":0,"n_instrument":0,"n_unverified":1,"n_honours":0,"n_violates":0,"n_no_contract":0,"n_pointer_only":1,"phrase":"0 ran · 1 unverified","sample_list":"/paper/structured-adversarial-attack-towards-general#ran","syntology_url":"https://syntology.ai/paper/1808.01664","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1808.01664"}},"official":{"repos":["KaidiXu/StrAttack"],"state":"official: harvested, nothing ran","n_ran":0,"n_constructed":0,"n_ran_no_instrument_failure":0,"n_unverified":1,"ran_from_kinds":[]}}},{"url":"/paper/evaluating-and-understanding-the-robustness","slug":"evaluating-and-understanding-the-robustness","title":"Evaluating and Understanding the Robustness of Adversarial Logit Pairing","date":"2018-07-26","arxiv_id":"1807.10272","repositories_listed":1,"syntology":{"n":5,"n_ran":0,"n_constructed":0,"n_ran_checked":0,"n_instrument":0,"n_unverified":5,"n_honours":0,"n_violates":0,"n_no_contract":0,"n_pointer_only":5,"phrase":"0 ran · 5 unverified","sample_list":"/paper/evaluating-and-understanding-the-robustness#ran","syntology_url":"https://syntology.ai/paper/1807.10272","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1807.10272"}},"official":{"repos":["labsix/adversarial-logit-pairing-analysis"],"state":"official: harvested, nothing ran","n_ran":0,"n_constructed":0,"n_ran_no_instrument_failure":0,"n_unverified":5,"ran_from_kinds":[]}}},{"url":"/paper/with-friends-like-these-who-needs-adversaries","slug":"with-friends-like-these-who-needs-adversaries","title":"With Friends Like These, Who Needs Adversaries?","date":"2018-07-11","arxiv_id":"1807.04200","repositories_listed":1,"syntology":null},{"url":"/paper/a-game-based-approximate-verification-of-deep","slug":"a-game-based-approximate-verification-of-deep","title":"A Game-Based Approximate Verification of Deep Neural Networks with Provable Guarantees","date":"2018-07-10","arxiv_id":"1807.03571","repositories_listed":1,"syntology":{"n":4,"n_ran":3,"n_constructed":0,"n_ran_checked":3,"n_instrument":0,"n_unverified":1,"n_honours":0,"n_violates":0,"n_no_contract":3,"n_pointer_only":0,"phrase":"3 ran (of which 0 constructed an object rather than computing a result; 3 with no instrument failure: 0 honoured, 0 violated, 3 with no contract checked; 0 where Syntology's instrument failed) · 1 unverified","sample_list":"/paper/a-game-based-approximate-verification-of-deep#ran","syntology_url":"https://syntology.ai/paper/1807.03571","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1807.03571"}},"official":{"repos":["TrustAI/DeepGame"],"state":"official (archive's flag): 3 ran","n_ran":3,"n_constructed":0,"n_ran_no_instrument_failure":3,"n_unverified":1,"ran_from_kinds":["official"]}}},{"url":"/paper/learning-visually-grounded-semantics-from","slug":"learning-visually-grounded-semantics-from","title":"Learning Visually-Grounded Semantics from Contrastive Adversarial Samples","date":"2018-06-27","arxiv_id":"1806.10348","repositories_listed":1,"syntology":{"n":15,"n_ran":14,"n_constructed":0,"n_ran_checked":12,"n_instrument":2,"n_unverified":1,"n_honours":0,"n_violates":0,"n_no_contract":12,"n_pointer_only":1,"phrase":"14 ran (of which 0 constructed an object rather than computing a result; 12 with no instrument failure: 0 honoured, 0 violated, 12 with no contract checked; 2 where Syntology's instrument failed) · 1 unverified","sample_list":"/paper/learning-visually-grounded-semantics-from#ran","syntology_url":"https://syntology.ai/paper/1806.10348","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1806.10348"}},"official":{"repos":["ExplorerFreda/VSE-C"],"state":"official (archive's flag): 14 ran","n_ran":14,"n_constructed":0,"n_ran_no_instrument_failure":12,"n_unverified":1,"ran_from_kinds":["official"]}}},{"url":"/paper/adversarial-attack-on-graph-structured-data","slug":"adversarial-attack-on-graph-structured-data","title":"Adversarial Attack on Graph Structured Data","date":"2018-06-06","arxiv_id":"1806.02371","repositories_listed":1,"syntology":null},{"url":"/paper/knowledge-distillation-with-adversarial","slug":"knowledge-distillation-with-adversarial","title":"Knowledge Distillation with Adversarial Samples Supporting Decision Boundary","date":"2018-05-15","arxiv_id":"1805.05532","repositories_listed":1,"syntology":{"n":4,"n_ran":4,"n_constructed":0,"n_ran_checked":3,"n_instrument":1,"n_unverified":0,"n_honours":0,"n_violates":0,"n_no_contract":3,"n_pointer_only":1,"phrase":"4 ran (of which 0 constructed an object rather than computing a result; 3 with no instrument failure: 0 honoured, 0 violated, 3 with no contract checked; 1 where Syntology's instrument failed) · 0 unverified","sample_list":"/paper/knowledge-distillation-with-adversarial#ran","syntology_url":"https://syntology.ai/paper/1805.05532","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1805.05532"}},"official":{"repos":["bhheo/BSS_distillation"],"state":"official (archive's flag): 4 ran","n_ran":4,"n_constructed":0,"n_ran_no_instrument_failure":3,"n_unverified":0,"ran_from_kinds":["official"]}}},{"url":"/paper/query-efficient-black-box-adversarial","slug":"query-efficient-black-box-adversarial","title":"Query-Efficient Black-box Adversarial Examples (superceded)","date":"2017-12-19","arxiv_id":"1712.07113","repositories_listed":1,"syntology":{"n":3,"n_ran":2,"n_constructed":0,"n_ran_checked":2,"n_instrument":0,"n_unverified":1,"n_honours":2,"n_violates":0,"n_no_contract":0,"n_pointer_only":3,"phrase":"2 ran (of which 0 constructed an object rather than computing a result; 2 with no instrument failure: 2 honoured, 0 violated, 0 with no contract checked; 0 where Syntology's instrument failed) · 1 unverified","sample_list":"/paper/query-efficient-black-box-adversarial#ran","syntology_url":"https://syntology.ai/paper/1712.07113","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1712.07113"}},"official":null}},{"url":"/paper/generating-natural-adversarial-examples","slug":"generating-natural-adversarial-examples","title":"Generating Natural Adversarial Examples","date":"2017-10-31","arxiv_id":"1710.11342","repositories_listed":1,"syntology":null},{"url":"/paper/adversarial-playground-a-visualization-suite","slug":"adversarial-playground-a-visualization-suite","title":"Adversarial-Playground: A Visualization Suite Showing How Adversarial Examples Fool Deep Learning","date":"2017-08-01","arxiv_id":"1708.00807","repositories_listed":1,"syntology":null},{"url":"/paper/adversarial-and-clean-data-are-not-twins","slug":"adversarial-and-clean-data-are-not-twins","title":"Adversarial and Clean Data Are Not Twins","date":"2017-04-17","arxiv_id":"1704.04960","repositories_listed":1,"syntology":null},{"url":"/paper/on-detecting-adversarial-perturbations","slug":"on-detecting-adversarial-perturbations","title":"On Detecting Adversarial Perturbations","date":"2017-02-14","arxiv_id":"1702.04267","repositories_listed":1,"syntology":null},{"url":"/paper/adversarial-images-for-variational","slug":"adversarial-images-for-variational","title":"Adversarial Images for Variational Autoencoders","date":"2016-12-01","arxiv_id":"1612.00155","repositories_listed":1,"syntology":null},{"url":null,"slug":"3dgaa-realistic-and-robust-3d-gaussian-based","title":"3DGAA: Realistic and Robust 3D Gaussian-based Adversarial Attack for Autonomous Driving","date":"2025-07-14","arxiv_id":"2507.09993","repositories_listed":0,"syntology":null},{"url":null,"slug":"3d-gaussian-splatting-driven-multi-view","title":"3D Gaussian Splatting Driven Multi-View Robust Physical Adversarial Camouflage Generation","date":"2025-07-02","arxiv_id":"2507.01367","repositories_listed":0,"syntology":null},{"url":null,"slug":"poster-enhancing-gnn-robustness-for-network","title":"Poster: Enhancing GNN Robustness for Network Intrusion Detection via Agent-based Analysis","date":"2025-06-25","arxiv_id":"2506.20806","repositories_listed":0,"syntology":null},{"url":null,"slug":"dro-augment-framework-robustness-by","title":"DRO-Augment Framework: Robustness by Synergizing Wasserstein Distributionally Robust Optimization and Data Augmentation","date":"2025-06-22","arxiv_id":"2506.17874","repositories_listed":0,"syntology":null},{"url":null,"slug":"doppelganger-method-breaking-role-consistency","title":"Doppelganger Method: Breaking Role Consistency in LLM Agent via Prompt-based Transferable Adversarial Attack","date":"2025-06-17","arxiv_id":"2506.14539","repositories_listed":0,"syntology":null},{"url":null,"slug":"alphabet-index-mapping-jailbreaking-llms","title":"Alphabet Index Mapping: Jailbreaking LLMs through Semantic Dissimilarity","date":"2025-06-15","arxiv_id":"2506.12685","repositories_listed":0,"syntology":null},{"url":null,"slug":"constraint-guided-prediction-refinement-via","title":"Constraint-Guided Prediction Refinement via Deterministic Diffusion Trajectories","date":"2025-06-15","arxiv_id":"2506.12911","repositories_listed":0,"syntology":null},{"url":null,"slug":"on-the-existence-of-consistent-adversarial","title":"On the existence of consistent adversarial attacks in high-dimensional linear classification","date":"2025-06-14","arxiv_id":"2506.12454","repositories_listed":0,"syntology":null},{"url":null,"slug":"second-order-state-hallucinations-for","title":"Second Order State Hallucinations for Adversarial Attack Mitigation in Formation Control of Multi-Agent Systems","date":"2025-06-14","arxiv_id":"2506.17283","repositories_listed":0,"syntology":null},{"url":null,"slug":"2506-10459","title":"Boosting Adversarial Transferability for Hyperspectral Image Classification Using 3D Structure-invariant Transformation and Intermediate Feature Distance","date":"2025-06-12","arxiv_id":"2506.10459","repositories_listed":0,"syntology":null},{"url":null,"slug":"2506-10685","title":"Unsourced Adversarial CAPTCHA: A Bi-Phase Adversarial CAPTCHA Framework","date":"2025-06-12","arxiv_id":"2506.10685","repositories_listed":0,"syntology":null},{"url":null,"slug":"a-look-at-adversarial-attacks-on-radio","title":"A look at adversarial attacks on radio waveforms from discrete latent space","date":"2025-06-11","arxiv_id":"2506.09896","repositories_listed":0,"syntology":null},{"url":null,"slug":"adversarial-attack-safety-alignment-alkali","title":"AdversariaL attacK sAfety aLIgnment(ALKALI): Safeguarding LLMs through GRACE: Geometric Representation-Aware Contrastive Enhancement- Introducing Adversarial Vulnerability Quality Index (AVQI)","date":"2025-06-10","arxiv_id":"2506.08885","repositories_listed":0,"syntology":null},{"url":null,"slug":"adversarial-threat-vectors-and-risk","title":"Adversarial Threat Vectors and Risk Mitigation for Retrieval-Augmented Generation Systems","date":"2025-05-30","arxiv_id":"2506.00281","repositories_listed":0,"syntology":null},{"url":null,"slug":"seeing-the-threat-vulnerabilities-in-vision","title":"Seeing the Threat: Vulnerabilities in Vision-Language Models to Adversarial Attack","date":"2025-05-28","arxiv_id":"2505.21967","repositories_listed":0,"syntology":null},{"url":null,"slug":"a-framework-for-adversarial-analysis-of","title":"A Framework for Adversarial Analysis of Decision Support Systems Prior to Deployment","date":"2025-05-27","arxiv_id":"2505.21414","repositories_listed":0,"syntology":null},{"url":null,"slug":"boosting-adversarial-transferability-via-high","title":"Boosting Adversarial Transferability via High-Frequency Augmentation and Hierarchical-Gradient Fusion","date":"2025-05-27","arxiv_id":"2505.21181","repositories_listed":0,"syntology":null},{"url":null,"slug":"tesser-transfer-enhancing-adversarial-attacks","title":"TESSER: Transfer-Enhancing Adversarial Attacks from Vision Transformers via Spectral and Semantic Regularization","date":"2025-05-26","arxiv_id":"2505.19613","repositories_listed":0,"syntology":null},{"url":null,"slug":"curvature-dynamic-black-box-attack-revisiting","title":"Curvature Dynamic Black-box Attack: revisiting adversarial robustness via dynamic curvature estimation","date":"2025-05-25","arxiv_id":"2505.19194","repositories_listed":0,"syntology":null},{"url":null,"slug":"ownership-verification-of-dnn-models-using","title":"Ownership Verification of DNN Models Using White-Box Adversarial Attacks with Specified Probability Manipulation","date":"2025-05-23","arxiv_id":"2505.17579","repositories_listed":0,"syntology":null},{"url":null,"slug":"towards-more-transferable-adversarial-attack","title":"Towards more transferable adversarial attack in black-box manner","date":"2025-05-23","arxiv_id":"2505.18097","repositories_listed":0,"syntology":null},{"url":null,"slug":"chain-of-thought-poisoning-attacks-against-r1","title":"Chain-of-Thought Poisoning Attacks against R1-based Retrieval-Augmented Generation Systems","date":"2025-05-22","arxiv_id":"2505.16367","repositories_listed":0,"syntology":null},{"url":null,"slug":"experimental-robustness-benchmark-of-quantum","title":"Experimental robustness benchmark of quantum neural network on a superconducting quantum processor","date":"2025-05-22","arxiv_id":"2505.16714","repositories_listed":0,"syntology":null},{"url":"/paper/tropical-attention-neural-algorithmic","slug":"tropical-attention-neural-algorithmic","title":"Tropical Attention: Neural Algorithmic Reasoning for Combinatorial Algorithms","date":"2025-05-22","arxiv_id":"2505.17190","repositories_listed":0,"syntology":{"n":9,"n_ran":9,"n_constructed":0,"n_ran_checked":9,"n_instrument":0,"n_unverified":0,"n_honours":0,"n_violates":0,"n_no_contract":9,"n_pointer_only":0,"phrase":"9 ran (of which 0 constructed an object rather than computing a result; 9 with no instrument failure: 0 honoured, 0 violated, 9 with no contract checked; 0 where Syntology's instrument failed) · 0 unverified","sample_list":"/paper/tropical-attention-neural-algorithmic#ran","syntology_url":"https://syntology.ai/paper/2505.17190","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2505.17190"}},"official":null}},{"url":null,"slug":"beyond-classification-evaluating-diffusion","title":"Beyond Classification: Evaluating Diffusion Denoised Smoothing for Security-Utility Trade off","date":"2025-05-21","arxiv_id":"2505.15594","repositories_listed":0,"syntology":null},{"url":null,"slug":"adverseness-vs-equilibrium-exploring-graph","title":"Adverseness vs. Equilibrium: Exploring Graph Adversarial Resilience through Dynamic Equilibrium","date":"2025-05-20","arxiv_id":"2505.14463","repositories_listed":0,"syntology":null},{"url":null,"slug":"evaloop-assessing-llm-robustness-in","title":"EVALOOP: Assessing LLM Robustness in Programming from a Self-consistency Perspective","date":"2025-05-18","arxiv_id":"2505.12185","repositories_listed":0,"syntology":null},{"url":"/paper/fable-a-localized-targeted-adversarial-attack","slug":"fable-a-localized-targeted-adversarial-attack","title":"FABLE: A Localized, Targeted Adversarial Attack on Weather Forecasting Models","date":"2025-05-17","arxiv_id":"2505.12167","repositories_listed":0,"syntology":{"n":9,"n_ran":6,"n_constructed":6,"n_ran_checked":6,"n_instrument":0,"n_unverified":3,"n_honours":0,"n_violates":0,"n_no_contract":6,"n_pointer_only":9,"phrase":"6 ran (of which 6 constructed an object rather than computing a result; 6 with no instrument failure: 0 honoured, 0 violated, 6 with no contract checked; 0 where Syntology's instrument failed) · 3 unverified; every one of the 6 samples that ran constructed an object rather than computing a result","sample_list":"/paper/fable-a-localized-targeted-adversarial-attack#ran","syntology_url":"https://syntology.ai/paper/2505.12167","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2505.12167"}},"official":null}},{"url":null,"slug":"no-query-no-access","title":"No Query, No Access","date":"2025-05-12","arxiv_id":"2505.07258","repositories_listed":0,"syntology":null},{"url":null,"slug":"input-specific-and-universal-adversarial","title":"Input-Specific and Universal Adversarial Attack Generation for Spiking Neural Networks in the Spiking Domain","date":"2025-05-07","arxiv_id":"2505.06299","repositories_listed":0,"syntology":null},{"url":null,"slug":"adversarial-attacks-in-multimodal-systems-a","title":"Adversarial Attacks in Multimodal Systems: A Practitioner's Survey","date":"2025-05-06","arxiv_id":"2505.03084","repositories_listed":0,"syntology":null},{"url":null,"slug":"rogue-cell-adversarial-attack-and-defense-in","title":"Rogue Cell: Adversarial Attack and Defense in Untrusted O-RAN Setup Exploiting the Traffic Steering xApp","date":"2025-05-03","arxiv_id":"2505.01816","repositories_listed":0,"syntology":null},{"url":null,"slug":"constrained-network-adversarial-attacks","title":"Constrained Network Adversarial Attacks: Validity, Robustness, and Transferability","date":"2025-05-02","arxiv_id":"2505.01328","repositories_listed":0,"syntology":null},{"url":null,"slug":"analysis-of-the-vulnerability-of-machine","title":"Analysis of the vulnerability of machine learning regression models to adversarial attacks using data from 5G wireless networks","date":"2025-05-01","arxiv_id":"2505.00487","repositories_listed":0,"syntology":null},{"url":null,"slug":"agate-stealthy-black-box-watermarking-for","title":"AGATE: Stealthy Black-box Watermarking for Multimodal Model Copyright Protection","date":"2025-04-28","arxiv_id":"2504.21044","repositories_listed":0,"syntology":null},{"url":null,"slug":"seeking-flat-minima-over-diverse-surrogates","title":"Seeking Flat Minima over Diverse Surrogates for Improved Adversarial Transferability: A Theoretical Framework and Algorithmic Instantiation","date":"2025-04-23","arxiv_id":"2504.16474","repositories_listed":0,"syntology":null},{"url":null,"slug":"hydra-an-agentic-reasoning-approach-for","title":"Hydra: An Agentic Reasoning Approach for Enhancing Adversarial Robustness and Mitigating Hallucinations in Vision-Language Models","date":"2025-04-19","arxiv_id":"2504.14395","repositories_listed":0,"syntology":null},{"url":null,"slug":"q-faker-query-free-hard-black-box-attack-via","title":"Q-FAKER: Query-free Hard Black-box Attack via Controlled Generation","date":"2025-04-18","arxiv_id":"2504.13551","repositories_listed":0,"syntology":null},{"url":null,"slug":"semdiff-generating-natural-unrestricted","title":"SemDiff: Generating Natural Unrestricted Adversarial Examples via Semantic Attributes Optimization in Diffusion Models","date":"2025-04-16","arxiv_id":"2504.11923","repositories_listed":0,"syntology":null},{"url":null,"slug":"bregman-linearized-augmented-lagrangian","title":"Bregman Linearized Augmented Lagrangian Method for Nonconvex Constrained Stochastic Zeroth-order Optimization","date":"2025-04-13","arxiv_id":"2504.09409","repositories_listed":0,"syntology":null},{"url":null,"slug":"toward-spiking-neural-network-local-learning","title":"Toward Spiking Neural Network Local Learning Modules Resistant to Adversarial Attacks","date":"2025-04-11","arxiv_id":"2504.08897","repositories_listed":0,"syntology":null},{"url":null,"slug":"towards-calibration-enhanced-network-by","title":"Towards Calibration Enhanced Network by Inverse Adversarial Attack","date":"2025-04-08","arxiv_id":"2504.06358","repositories_listed":0,"syntology":null},{"url":null,"slug":"secure-diagnostics-adversarial-robustness","title":"Secure Diagnostics: Adversarial Robustness Meets Clinical Interpretability","date":"2025-04-07","arxiv_id":"2504.05483","repositories_listed":0,"syntology":null},{"url":null,"slug":"moving-target-defense-against-adversarial","title":"Moving Target Defense Against Adversarial False Data Injection Attacks In Power Grids","date":"2025-04-03","arxiv_id":"2504.03065","repositories_listed":0,"syntology":null},{"url":null,"slug":"overlap-aware-feature-learning-for-robust","title":"Overlap-Aware Feature Learning for Robust Unsupervised Domain Adaptation for 3D Semantic Segmentation","date":"2025-04-02","arxiv_id":"2504.01668","repositories_listed":0,"syntology":null},{"url":null,"slug":"tenad-a-tensor-based-low-rank-black-box","title":"TenAd: A Tensor-based Low-rank Black Box Adversarial Attack for Video Classification","date":"2025-04-01","arxiv_id":"2504.01228","repositories_listed":0,"syntology":null},{"url":null,"slug":"unleashing-the-power-of-pre-trained-encoders","title":"Unleashing the Power of Pre-trained Encoders for Universal Adversarial Attack Detection","date":"2025-04-01","arxiv_id":"2504.00429","repositories_listed":0,"syntology":null},{"url":null,"slug":"textit-agents-under-siege-breaking-pragmatic","title":"$\\textit{Agents Under Siege}$: Breaking Pragmatic Multi-Agent LLM Systems with Optimized Prompt Attacks","date":"2025-03-31","arxiv_id":"2504.00218","repositories_listed":0,"syntology":null},{"url":null,"slug":"towards-benchmarking-and-assessing-the-safety","title":"Towards Benchmarking and Assessing the Safety and Robustness of Autonomous Driving on Safety-critical Scenarios","date":"2025-03-31","arxiv_id":"2503.23708","repositories_listed":0,"syntology":null},{"url":null,"slug":"robust-deep-reinforcement-learning-in","title":"Robust Deep Reinforcement Learning in Robotics via Adaptive Gradient-Masked Adversarial Attacks","date":"2025-03-26","arxiv_id":"2503.20844","repositories_listed":0,"syntology":null},{"url":null,"slug":"state-aware-perturbation-optimization-for","title":"State-Aware Perturbation Optimization for Robust Deep Reinforcement Learning","date":"2025-03-26","arxiv_id":"2503.20613","repositories_listed":0,"syntology":null},{"url":null,"slug":"imf-implicit-fingerprint-for-large-language","title":"ImF: Implicit Fingerprint for Large Language Models","date":"2025-03-25","arxiv_id":"2503.21805","repositories_listed":0,"syntology":null},{"url":null,"slug":"make-the-most-of-everything-further","title":"Make the Most of Everything: Further Considerations on Disrupting Diffusion-based Customization","date":"2025-03-18","arxiv_id":"2503.13945","repositories_listed":0,"syntology":null},{"url":null,"slug":"augmented-adversarial-trigger-learning","title":"Augmented Adversarial Trigger Learning","date":"2025-03-16","arxiv_id":"2503.12339","repositories_listed":0,"syntology":null},{"url":null,"slug":"relate-resilient-learner-selection-for","title":"ReLATE: Resilient Learner Selection for Multivariate Time-Series Classification Against Adversarial Attacks","date":"2025-03-10","arxiv_id":"2503.07882","repositories_listed":0,"syntology":null}],"record_sha256":"30b6abbb45af695a121f6f121db17fcb9e95551ee9026ca15362584d10dec71c","record_changed_at":"2026-09-28","record_changed_at_basis":"first_hashed"}