{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,21]],"date-time":"2025-08-21T17:27:33Z","timestamp":1755797253196,"version":"3.44.0"},"reference-count":59,"publisher":"Association for Computing Machinery (ACM)","issue":"4","content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Intell. Syst. Technol."],"published-print":{"date-parts":[[2025,8,31]]},"abstract":"<jats:p>Our article introduces a novel defense mechanism against black-box attacks, where attackers exploit the victim model as an oracle to craft adversarial examples. Unlike traditional pre-processing defenses that rely on sanitizing input samples, our stateless strategy directly counters the attack process itself. For each query, we evaluate a counter-sample, an optimized version of the original sample, designed to thwart the attacker\u2019s objective. By responding to every black-box query with a targeted white-box optimization, our strategy introduces a strategic asymmetry that significantly advantages the defender.<\/jats:p>\n          <jats:p>Our approach proves to be highly effective against state-of-the-art black-box attacks, outperforming existing defenses on both CIFAR-10 and ImageNet datasets. Specifically, our method achieves an average Attack Failure Rate (AFR) of 74.7% (up from 13%) on ImageNet and 67.7% (up from 3.5%) on CIFAR-10 when tested against 10 state-of-the-art query-based black-box attacks. Moreover, it maintains the model\u2019s performance on legitimate inputs, with accuracy (ACC) reduced by only 0.7% on ImageNet and 0.9% on CIFAR-10. This is in stark contrast to other defenses tested, which can cause accuracy drops of up to 50%. Such a modest decrease ensures negligible performance degradation on legitimate tasks.<\/jats:p>\n          <jats:p>Furthermore, we demonstrate that our defense exhibits superior robustness across datasets and attack scenarios, including adaptive attacks specifically designed to try to bypass our method. This robustness highlights the strength and adaptability of our approach in countering adversarial threats.<\/jats:p>","DOI":"10.1145\/3744657","type":"journal-article","created":{"date-parts":[[2025,6,13]],"date-time":"2025-06-13T12:04:52Z","timestamp":1749816292000},"page":"1-23","update-policy":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Counter-Samples: A Stateless Strategy to Neutralize Black-Box Adversarial Attacks"],"prefix":"10.1145","volume":"16","author":[{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0009-0008-9450-642X","authenticated-orcid":false,"given":"Roey","family":"Bokobza","sequence":"first","affiliation":[{"name":"Software and Information Systems Engineering, Ben-Gurion University of the Negev, Beer-Sheva, Israel"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0000-0001-6367-2734","authenticated-orcid":false,"given":"Yisroel","family":"Mirsky","sequence":"additional","affiliation":[{"name":"Software and Information Systems Engineering, Ben-Gurion University of the Negev, Beer-Sheva, Israel"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2025,8,18]]},"reference":[{"key":"e_1_3_2_2_2","volume-title":"International Conference on Learning Representations","author":"Al-Dujaili Abdullah","year":"2019","unstructured":"Abdullah Al-Dujaili and Una-May O\u2019Reilly. 2019. Sign bits are all you need for black-box attacks. In International Conference on Learning Representations."},{"key":"e_1_3_2_3_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2024.125840"},{"key":"e_1_3_2_4_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58592-1_29"},{"key":"e_1_3_2_5_2","first-page":"274","volume-title":"International Conference on Machine Learning. PMLR","author":"Athalye Anish","year":"2018","unstructured":"Anish Athalye, Nicholas Carlini, and David Wagner. 2018. Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples. In International Conference on Machine Learning. PMLR, 274\u2013283."},{"key":"e_1_3_2_6_2","first-page":"284","volume-title":"International Conference on Machine Learning. PMLR","author":"Athalye Anish","year":"2018","unstructured":"Anish Athalye, Logan Engstrom, Andrew Ilyas, and Kevin Kwok. 2018. Synthesizing robust adversarial examples. In International Conference on Machine Learning. PMLR, 284\u2013293."},{"key":"e_1_3_2_7_2","doi-asserted-by":"publisher","DOI":"10.1109\/TGRS.2024.3436841"},{"key":"e_1_3_2_8_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10489-023-05264-2"},{"key":"e_1_3_2_9_2","unstructured":"At\u0131l\u0131m G\u00fcne\u015f Baydin Barak A. Pearlmutter Don Syme Frank Wood and Philip Torr. 2022. Gradients without backpropagation. arXiv:2202.08587. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/arxiv.org\/abs\/2202.08587"},{"key":"e_1_3_2_10_2","unstructured":"Wieland Brendel Jonas Rauber and Matthias Bethge. 2017. Decision-based adversarial attacks: Reliable attacks against black-box machine learning models. arXiv:1712.04248. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/arxiv.org\/abs\/1712.04248"},{"key":"e_1_3_2_11_2","doi-asserted-by":"publisher","DOI":"10.1109\/WACV51458.2022.00387"},{"key":"e_1_3_2_12_2","first-page":"5348","article-title":"Amit Roy-Chowdhury, and Salman Asif. 2022. Blackbox attacks via surrogate ensemble search","volume":"35","author":"Cai Zikui","unstructured":"Zikui Cai, Chengyu Song, Srikanth Krishnamurthy, Amit Roy-Chowdhury, and Salman Asif. 2022. Blackbox attacks via surrogate ensemble search. In Advances in Neural Information Processing Systems, Vol. 35, 5348\u20135362.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_13_2","unstructured":"Paul Caillon Erwan Fagnou Blaise Delattre and Alexandre Allauzen. 2024. Backpropagation-free learning through gradient aligned feedbacks. In ICLR. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/openreview.net\/forum?id=oRPXPoTXYz"},{"key":"e_1_3_2_14_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"e_1_3_2_15_2","unstructured":"Patrick Chao Alexander Robey Edgar Dobriban Hamed Hassani George J. Pappas and Eric Wong. 2023. Jailbreaking black box large language models in twenty queries. arXiv:2310.08419. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/arxiv.org\/abs\/2310.08419"},{"key":"e_1_3_2_16_2","unstructured":"Huanran Chen Yichi Zhang Yinpeng Dong Xiao Yang Hang Su and Jun Zhu. 2023. Rethinking model ensemble in transfer-based adversarial attacks. arXiv:2303.09105. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/arxiv.org\/abs\/2303.09105"},{"key":"e_1_3_2_17_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00045"},{"key":"e_1_3_2_18_2","doi-asserted-by":"publisher","DOI":"10.1145\/3385003.3410925"},{"key":"e_1_3_2_19_2","unstructured":"Minhao Cheng Simranjit Singh Patrick Chen Pin-Yu Chen Sijia Liu and Cho-Jui Hsieh. 2019. Sign-opt: A query-efficient hard-label adversarial attack. arXiv:1909.10773. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/arxiv.org\/abs\/1909.10773"},{"key":"e_1_3_2_20_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"e_1_3_2_21_2","unstructured":"Gintare Karolina Dziugaite Zoubin Ghahramani and Daniel M. Roy. 2016. A study of the effect of JPG compression on adversarial images. arXiv:1608.00853. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/arxiv.org\/abs\/1608.00853"},{"key":"e_1_3_2_22_2","unstructured":"Ian J. Goodfellow Jonathon Shlens and Christian Szegedy. 2014. Explaining and harnessing adversarial examples. arXiv:1412.6572. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/arxiv.org\/abs\/1412.6572"},{"key":"e_1_3_2_23_2","first-page":"2484","volume-title":"International Conference on Machine Learning. PMLR","author":"Guo Chuan","year":"2019","unstructured":"Chuan Guo, Jacob Gardner, Yurong You, Andrew Gordon Wilson, and Kilian Weinberger. 2019. Simple black-box adversarial attacks. In International Conference on Machine Learning. PMLR, 2484\u20132493."},{"key":"e_1_3_2_24_2","doi-asserted-by":"publisher","DOI":"10.3390\/s24175507"},{"key":"e_1_3_2_25_2","first-page":"2137","volume-title":"International Conference on Machine Learning. PMLR","author":"Ilyas Andrew","year":"2018","unstructured":"Andrew Ilyas, Logan Engstrom, Anish Athalye, and Jessy Lin. 2018. Black-box adversarial attacks with limited queries and information. In International Conference on Machine Learning. PMLR, 2137\u20132146."},{"key":"e_1_3_2_26_2","unstructured":"Andrew Ilyas Logan Engstrom and Aleksander Madry. 2018. Prior convictions: Black-box adversarial attacks with bandits and priors. arXiv:1807.07978. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/arxiv.org\/abs\/1807.07978"},{"key":"e_1_3_2_27_2","first-page":"130","volume-title":"European Conference on Computer Vision","author":"Kang Caixin","year":"2024","unstructured":"Caixin Kang, Yinpeng Dong, Zhengyi Wang, Shouwei Ruan, Yubo Chen, Hang Su, and Xingxing Wei. 2024. Diffender: Diffusion-based adversarial defense against patch attacks. In European Conference on Computer Vision. Springer, 130\u2013147."},{"key":"e_1_3_2_28_2","unstructured":"Alex Krizhevsky. 2009.\u00a0Learning Multiple Layers of Features from Tiny Images. Master's thesis. University of Toronto."},{"key":"e_1_3_2_29_2","unstructured":"Guang Lin Duc Thien Nguyen Zerui Tao Konstantinos Slavakis Toshihisa Tanaka and Qibin Zhao. 2025. Model-free adversarial purification via coarse-to-fine tensor network representation. arXiv:2502.17972. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/arxiv.org\/abs\/2502.17972"},{"key":"e_1_3_2_30_2","unstructured":"Guang Lin and Qibin Zhao. 2024. Large language model sentinel: LLM agent for adversarial purification. arXiv:2405.20770. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/arxiv.org\/abs\/2405.20770"},{"key":"e_1_3_2_31_2","volume-title":"International Conference on Learning Representations (ICLR)","author":"Liu Sijia","year":"2019","unstructured":"Sijia Liu, Pin-Yu Chen, Xiangyi Chen, and Mingyi Hong. 2019. signSGD via zeroth-order oracle. In International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_32_2","unstructured":"Max Losch Mohamed Omran David Stutz Mario Fritz and Bernt Schiele. 2024. On adversarial training without perturbing all examples. In The Twelfth International Conference on Learning Representations."},{"issue":"1","key":"e_1_3_2_33_2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3485133","article-title":"Adversarial machine learning in image classification: A survey toward the defender\u2019s perspective","volume":"55","author":"Machado Gabriel Resende","year":"2021","unstructured":"Gabriel Resende Machado, Eug\u00eanio Silva, and Ronaldo Ribeiro Goldschmidt. 2021. Adversarial machine learning in image classification: A survey toward the defender\u2019s perspective. ACM Computing Surveys 55, 1 (2021), 1\u201338.","journal-title":"ACM Computing Surveys"},{"key":"e_1_3_2_34_2","unstructured":"Aleksander Madry Aleksandar Makelov Ludwig Schmidt Dimitris Tsipras and Adrian Vladu. 2017. Towards deep learning models resistant to adversarial attacks. arXiv:1706.06083. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/arxiv.org\/abs\/1706.06083"},{"key":"e_1_3_2_35_2","doi-asserted-by":"publisher","DOI":"10.3390\/ai5040101"},{"key":"e_1_3_2_36_2","first-page":"4636","volume-title":"International Conference on Machine Learning. PMLR","author":"Moon Seungyong","year":"2019","unstructured":"Seungyong Moon, Gaon An, and Hyun Oh Song. 2019. Parsimonious black-box adversarial attacks via efficient combinatorial optimization. In International Conference on Machine Learning. PMLR, 4636\u20134645."},{"key":"e_1_3_2_37_2","unstructured":"Furkan Mumcu and Yasin Yilmaz. 2024. Detecting adversarial examples. arXiv:2410.17442. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/arxiv.org\/abs\/2410.17442"},{"key":"e_1_3_2_38_2","doi-asserted-by":"publisher","DOI":"10.9734\/ajrcos\/2024\/v17i10505"},{"key":"e_1_3_2_39_2","doi-asserted-by":"publisher","DOI":"10.1109\/WACV57701.2024.00394"},{"key":"e_1_3_2_40_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2025.3542825"},{"key":"e_1_3_2_41_2","unstructured":"Jonathan Peck and Bart Goossens. 2024. Robust width: A lightweight and certifiable adversarial defense. arXiv:2405.15971. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/arxiv.org\/abs\/2405.15971"},{"issue":"2","key":"e_1_3_2_42_2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3706061","article-title":"AED-PADA: Improving generalizability of adversarial example detection via principal adversarial domain adaptation","volume":"21","author":"Peng Heqi","year":"2025","unstructured":"Heqi Peng, Yunhong Wang, Ruijie Yang, Beichen Li, Rui Wang, and Yuanfang Guo. 2025. AED-PADA: Improving generalizability of adversarial example detection via principal adversarial domain adaptation. ACM Transactions on Multimedia Computing, Communications and Applications 21, 2 (2025), 1\u201324.","journal-title":"ACM Transactions on Multimedia Computing, Communications and Applications"},{"key":"e_1_3_2_43_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i19.30150"},{"key":"e_1_3_2_44_2","first-page":"7650","article-title":"Random noise defense against query-based black-box attacks","volume":"34","author":"Qin Zeyu","year":"2021","unstructured":"Zeyu Qin, Yanbo Fan, Hongyuan Zha, and Baoyuan Wu. 2021. Random noise defense against query-based black-box attacks. In Advances in Neural Information Processing Systems 34 (2021), 7650\u20137663.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_45_2","unstructured":"Zeyu Qin Xuanchen Yan and Baoyuan Wu. 2022. BlackboxBench (Python Library). Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/github.com\/SCLBD\/BlackboxBench"},{"key":"e_1_3_2_46_2","doi-asserted-by":"publisher","DOI":"10.3934\/publichealth.2024004"},{"key":"e_1_3_2_47_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00847"},{"key":"e_1_3_2_48_2","unstructured":"Pouya Samangouei Maya Kabkab and Rama Chellappa. 2018. Defense-GAN: Protecting classifiers against adversarial attacks using generative models. arXiv:1805.06605. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/arxiv.org\/abs\/1805.06605"},{"key":"e_1_3_2_49_2","unstructured":"Yang Song Taesup Kim Sebastian Nowozin Stefano Ermon and Nate Kushman. 2017. Pixeldefend: Leveraging generative models to understand and defend against adversarial examples. arXiv:1710.10766. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/arxiv.org\/abs\/1710.10766"},{"key":"e_1_3_2_50_2","unstructured":"Christian Szegedy Wojciech Zaremba Ilya Sutskever Joan Bruna Dumitru Erhan Ian Goodfellow and Rob Fergus. 2013. Intriguing properties of neural networks. arXiv:1312.6199. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/arxiv.org\/abs\/1312.6199"},{"key":"e_1_3_2_51_2","doi-asserted-by":"publisher","DOI":"10.3390\/a17030103"},{"key":"e_1_3_2_52_2","doi-asserted-by":"publisher","DOI":"10.21437\/Interspeech.2024-855"},{"key":"e_1_3_2_53_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2024.127863"},{"key":"e_1_3_2_54_2","unstructured":"Boxi Wu Heng Pan Li Shen Jindong Gu Shuai Zhao Zhifeng Li Deng Cai Xiaofei He and Wei Liu. 2021. Attacking adversarial attacks as a defense. arXiv:2106.04938. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/arxiv.org\/abs\/2106.04938"},{"issue":"7","key":"e_1_3_2_55_2","doi-asserted-by":"crossref","first-page":"24","DOI":"10.1016\/j.cja.2023.12.009","article-title":"Multi-source information fusion: Progress and future","volume":"37","author":"Xinde L. I.","year":"2024","unstructured":"L. I. Xinde, Fir Dunkin, and Jean Dezert. 2024. Multi-source information fusion: Progress and future. Chinese Journal of Aeronautics 37, 7 (2024), 24\u201358.","journal-title":"Chinese Journal of Aeronautics"},{"key":"e_1_3_2_56_2","unstructured":"Weilin Xu David Evans and Yanjun Qi. 2017. Feature squeezing: Detecting adversarial examples in deep neural networks. arXiv:1704.01155. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/arxiv.org\/abs\/1704.01155"},{"key":"e_1_3_2_57_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICMLA51294.2020.00226"},{"key":"e_1_3_2_58_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00335"},{"issue":"1","key":"e_1_3_2_59_2","doi-asserted-by":"crossref","first-page":"e0317023","DOI":"10.1371\/journal.pone.0317023","article-title":"Avoiding catastrophic overfitting in fast adversarial training with adaptive similarity step size","volume":"20","author":"Zhao Jie-Chao","year":"2025","unstructured":"Jie-Chao Zhao, Jin Ding, Yong-Zhi Sun, Ping Tan, Ji-En Ma, and You-Tong Fang. 2025. Avoiding catastrophic overfitting in fast adversarial training with adaptive similarity step size. PLoS One 20, 1 (2025), e0317023.","journal-title":"PLoS One"},{"key":"e_1_3_2_60_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.02291"}],"container-title":["ACM Transactions on Intelligent Systems and Technology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/dl.acm.org\/doi\/pdf\/10.1145\/3744657","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,18]],"date-time":"2025-08-18T17:49:48Z","timestamp":1755539388000},"score":1,"resource":{"primary":{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/dl.acm.org\/doi\/10.1145\/3744657"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,8,18]]},"references-count":59,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2025,8,31]]}},"alternative-id":["10.1145\/3744657"],"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1145\/3744657","relation":{},"ISSN":["2157-6904","2157-6912"],"issn-type":[{"type":"print","value":"2157-6904"},{"type":"electronic","value":"2157-6912"}],"subject":[],"published":{"date-parts":[[2025,8,18]]},"assertion":[{"value":"2024-09-23","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-05-29","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-08-18","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}