{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,6,26]],"date-time":"2024-06-26T00:16:27Z","timestamp":1719360987922},"reference-count":68,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100012389","name":"Institute of Information & Communications Technology Planning & Evaluation","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100012389","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Korean Government","award":["RS-2022-00167169"]},{"name":"IITP"},{"name":"Korean Government (MSIT) [Artificial Intelligence Convergence Innovation Human Resources Development (Kyung Hee University)]","award":["RS-2022-00155911"]},{"name":"Convergence Security Core Talent Training Business Support Program","award":["IITP-2023-RS-2023-00266615"]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Access"],"published-print":{"date-parts":[[2024]]},"DOI":"10.1109\/access.2024.3407097","type":"journal-article","created":{"date-parts":[[2024,5,30]],"date-time":"2024-05-30T17:53:28Z","timestamp":1717091608000},"page":"80770-80780","source":"Crossref","is-referenced-by-count":0,"title":["D-BADGE: Decision-Based Adversarial Batch Attack With Directional Gradient Estimation"],"prefix":"10.1109","volume":"12","author":[{"ORCID":"http:\/\/orcid.org\/0009-0003-4912-2084","authenticated-orcid":false,"given":"Geunhyeok","family":"Yu","sequence":"first","affiliation":[{"name":"Department of Software Convergence, Kyung Hee University, Yongin-si, Republic of Korea"}]},{"given":"Minwoo","family":"Jeon","sequence":"additional","affiliation":[{"name":"Department of Software Convergence, Kyung Hee University, Yongin-si, Republic of Korea"}]},{"ORCID":"http:\/\/orcid.org\/0000-0003-3241-8455","authenticated-orcid":false,"given":"Hyoseok","family":"Hwang","sequence":"additional","affiliation":[{"name":"Department of Software Convergence, Kyung Hee University, Yongin-si, Republic of Korea"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1007\/s13735-017-0141-z"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2016.12.038"},{"key":"ref3","article-title":"Intriguing properties of neural networks","author":"Szegedy","year":"2013","journal-title":"arXiv:1312.6199"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2807385"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00033"},{"key":"ref6","first-page":"9706","article-title":"Variational model inversion attacks","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"34","author":"Wang"},{"key":"ref7","first-page":"1309","article-title":"Exploring connections between active learning and model extraction","volume-title":"Proc. 29th USENIX Conf. Secur. Symp.","author":"Chandrasekaran"},{"key":"ref8","first-page":"1345","article-title":"High accuracy and high fidelity extraction of neural networks","volume-title":"Proc. 29th USENIX Conf. Secur. Symp.","author":"Jagielski"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.17"},{"key":"ref11","article-title":"Decision-based universal adversarial attack","author":"Wu","year":"2020","journal-title":"arXiv:2009.07024"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2019.04.014"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01183"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01307"},{"key":"ref15","article-title":"Decision-based adversarial attacks: Reliable attacks against black-box machine learning models","author":"Brendel","year":"2017","journal-title":"arXiv:1712.04248"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00506"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00668"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00045"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00893"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00084"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1145\/3422622"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00465"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00444"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140448"},{"key":"ref26","first-page":"2484","article-title":"Simple black-box adversarial attacks","volume-title":"Proc. 36th Int. Conf. Mach. Learn.","author":"Guo"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1007\/s10208-015-9296-2"},{"key":"ref28","first-page":"1","article-title":"Improving black-box adversarial attacks with a transfer-based prior","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"32","author":"Cheng"},{"key":"ref29","first-page":"1","article-title":"Query efficient decision based sparse attacks against black-box deep learning models","volume-title":"Proc. 10th Int. Conf. Learn. Represent.","author":"Vo"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.03762"},{"key":"ref31","article-title":"An image is worth 16\u00d716 words: Transformers for image recognition at scale","author":"Dosovitskiy","year":"2020","journal-title":"arXiv:2010.11929"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00986"},{"key":"ref33","first-page":"2137","article-title":"Black-box adversarial attacks with limited queries and information","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Ilyas"},{"key":"ref34","article-title":"Evolution strategies as a scalable alternative to reinforcement learning","author":"Salimans","year":"2017","journal-title":"arXiv:1703.03864"},{"key":"ref35","article-title":"Black-box adversarial attack with transferable model-based embedding","author":"Huang","year":"2019","journal-title":"arXiv:1911.07140"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/9.119632"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/ACC.2001.945806"},{"key":"ref38","first-page":"5025","article-title":"Adversarial risk and the dangers of evaluating against weak attacks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Uesato"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.02320"},{"key":"ref40","first-page":"543","article-title":"A method for solving the convex programming problem with convergence rate O(1\/k2)","volume":"269","author":"Nesterov","year":"1983","journal-title":"Proc. USSR Acad. Sci."},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/WACV51458.2022.00411"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1145\/3580305.3599461"},{"key":"ref43","article-title":"Geometry-aware instance-reweighted adversarial training","author":"Zhang","year":"2020","journal-title":"arXiv:2010.01736"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1002\/j.1538-7305.1950.tb00463.x"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.1962.1057683"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/TAC.2021.3075669"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref48","article-title":"Very deep convolutional networks for large-scale image recognition","volume-title":"Proc. 3rd Int. Conf. Learn. Represent.","author":"Simonyan"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00474"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.634"},{"key":"ref51","article-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref54","first-page":"14900","article-title":"Anti-backdoor learning: Training clean models on poisoned data","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"34","author":"Li"},{"key":"ref55","article-title":"SGDR: Stochastic gradient descent with warm restarts","author":"Loshchilov","year":"2016","journal-title":"arXiv:1608.03983"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1145\/3065386"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v37i9.26331"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00754"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i6.28427"},{"key":"ref60","first-page":"1","article-title":"Understanding and improving ensemble adversarial defense","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"36","author":"Deng"},{"key":"ref61","first-page":"4970","article-title":"Improving adversarial robustness via promoting ensemble diversity","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Pang"},{"key":"ref62","first-page":"5505","article-title":"DVERGE: Diversifying vulnerabilities for enhanced robust generation of ensembles","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"33","author":"Yang"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW59228.2023.00236"},{"key":"ref64","first-page":"2437","article-title":"QFA2SR: Query-free adversarial transfer attacks to speaker recognition systems","volume-title":"Proc. 32nd USENIX Secur. Symp.","author":"Chen"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1126\/science.aaw4399"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.3390\/s23010175"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v36i2.20072"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2022.3166765"}],"container-title":["IEEE Access"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/6287639\/10380310\/10542123.pdf?arnumber=10542123","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,6,25]],"date-time":"2024-06-25T21:13:54Z","timestamp":1719350034000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10542123\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"references-count":68,"URL":"https:\/\/doi.org\/10.1109\/access.2024.3407097","relation":{},"ISSN":["2169-3536"],"issn-type":[{"value":"2169-3536","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024]]}}}