Research
On-device research index

arXiv research

A locally-built, LLM-digested index of recent arXiv papers in quant finance, geometry/topology, and statistical ML — keyword search served straight from SQLite on this machine.

169,236 papers · 148 categories

Trend · papers per month

65130195260 · Jun 202019922001200920182026
48 results for Black-box Classifiers

New attacks fool black-box classifiers under limited query and partial information settings.

problem Adversarial attacks on black-box neural networks with limited query access and partial information.
method Developed new attacks for query-limited, partial-information, and label-only threat models.
result Effective attacks against real-world classifiers under realistic threat models.

Paper presents mdfa to identify victims of discrimination in black box classifiers.

problem Identifying victims of discrimination in black box classifiers.
method Reduces discrimination measurement to matching distributions and sensitive attribute coincidence prediction.
result Identifies African-American individuals at high risk of violent recidivism.

Paper introduces active Bayesian method for assessing black-box classifiers efficiently.

problem Need to assess performance of black-box classifiers reliably with limited labels.
method Develops inference strategies and proposes active Bayesian framework for efficient instance selection.
result Significant gains in performance assessment with fewer labels compared to traditional methods.

Interpretable semi-supervised classifier for black-box models with two self-labeling strategies.

problem Lack of labeled data and difficulty in explaining black-box models.
method Combines black-box and white-box approaches for self-labeling and prediction.
result Superior prediction rates and interpretability compared to state-of-the-art classifiers.

This paper finds universal perturbations to fool black-box ML classifiers.

problem Breaking security through obscurity in black-box ML settings.
method Zeroth-order optimization for finding universal adversarial perturbations in a black-box setting.
result State-of-the-art ML classifiers can be fooled with a single imperceptible image perturbation.

Bayesian model explains and improves black-box estimators for class distribution.

problem Calibrating probabilistic classifiers and uncertainty quantification for unlabeled data.
method Introduced a Bayesian model approximating the ground-truth generative process, using efficient MCMC sampling.
result The Bayesian model is competitive and sometimes superior to established point estimators.

This paper explores how the generalization of substitute classifiers affects the success of black-box adversarial attacks.

problem Understanding the factors driving the transferability of black-box adversarial examples.
method Max-min adversarial example game framework and theoretical generalization bounds.
result Substitute NN with better generalization behavior results in more transferable adversarial examples.

Interpretable companion model for black-box classifiers.

problem Dilemma between interpretable and black-box models.
method Trains a companion model from data and black-box model predictions, optimizing a combination of accuracy and complexity.
result Companion model provides interpretable predictions with a slight accuracy loss for user choice.

Detects and corrects label shift in medical diagnoses.

problem Distribution shift between training and test sets in medical diagnosis.
method Black Box Shift Estimation (BBSE) to estimate test distribution and correct classifiers.
result Consistent and accurate estimates of test distribution and improved classifier performance.

A simple patch copying method reduces black-box adversarial attack queries by 81%.

problem The effectiveness of black-box adversarial attacks depends on the initialization method.
method Copying small patches from other images as initialization points.
result Reduces the number of queries required for a state-of-the-art Boundary Attack by 81%

xGEMs explain black-box models by exploring data manifolds.

problem Understanding the behavior of black-box classifiers.
method Train an unsupervised generative model to represent the data manifold and perturb data points to analyze model behavior.
result Detect and quantify bias in model learning and changes in model behavior over training.

Recent work in model-agnostic explanations of black-box machine learning has demonstrated that interpretability of complex models does not have to come at the cost of accuracy or model flexibility. However, it is not clear what kind of explanations, such as linear models, decision trees, and rule lists, are the appropr…

2016-11-22abs ↗pdf ↗

Invertible networks help explain decisions and identify important features.

problem Interpreting and explaining the decisions of black-box neural networks.
method Two-stage approach: invertible transformation to feature space and linear classifier. Determining decision boundaries and feature importance using local linear models.
result Ability to explain decisions and identify important features in neural networks.

DEceit constructs effective universal pixel-restricted perturbations for deep image classifiers.

problem Creating effective universal pixel-restricted perturbations for deep neural networks.
method DEceit algorithm for black-box feedback, targeting 10% of pixels in images.
result Perturbing only 10% of pixels achieves high Fooling Rate and visual similarity.

This paper addresses the importance of defining locality for accurate surrogate explanations.

problem Accurate approximation of local black-box decision boundaries for generating explanations.
method Proposes a novel approach to generate surrogate-based explanations centered on relevant places of the decision boundary, rather than on predictions.
result The proposed approach outperforms state-of-the-art methods and a straightforward improvement thereof on UCI datasets.

New research shows many recent defenses against adversarial examples are ineffective against black-box attacks.

problem The robustness of recent defenses against adversarial examples is insufficient, especially against black-box attacks.
method Evaluation of nine defenses on two black-box adversarial models and six attacks on CIFAR-10 and Fashion-MNIST datasets.
result Most recent defenses provide only marginal improvements in security (<25%<25\%) compared to undefended networks.

Paper proposes a new Hessian-aware zeroth-order optimization for improving black-box adversarial attacks.

problem Improving black-box adversarial attacks on neural networks.
method Introduces a Hessian-aware zeroth-order optimization algorithm called ZO-HessAware.
result ZO-HessAware achieves improved success rates with lower query complexity.

Study adversarial perturbations in classification, analyzing learning and certification.

problem Formal study of classification under adversarial perturbations from both learner and third-party perspectives.
method PAC-type semi-supervised learning framework, black-box certification under limited query budget, adversary analysis.
result Existence of a polynomial query complexity adversary implies the existence of a sample efficient robust learner.

New method generates reliable adversarial examples with fewer queries.

problem Neural networks are vulnerable to adversarial examples in black-box settings.
method Natural evolution strategies and targeted attacks in partial information settings.
result Successfully performed targeted adversarial attack on Google Cloud Vision API.

Efficient method reduces black-box adversarial queries for neural networks.

problem Solving for adversarial examples in black-box settings with limited query access.
method Efficient combinatorial optimization surrogate for gradient estimation.
result State-of-the-art black-box attack performance with reduced query count.

A new algorithm for optimizing huge-scale black-box problems with reduced memory usage.

problem Optimizing huge-scale black-box problems with limited vector operations.
method ZO-BCD algorithm for zeroth-order optimization with reduced memory footprint.
result ZO-BCD achieves state-of-the-art adversarial attack success rate of 97.9%.

REST improves robustness of black-box models to geometric transformations.

problem Overconfident incorrect predictions on out-of-distribution samples.
method REinforcement Spatial Transform learner (REST) that transforms input data into in-distribution samples.
result Improves robustness to geometric transformations and sample efficiency.

Generative GAN improves classifier performance with limited training data.

problem Limited training data for black-box API attacks.
method Generative adversarial network (GAN) to generate synthetic training data.
result Improves classifier performance with synthetic data.

P-BO reduces black-box adversarial attacks by 10x with Bayesian optimization and function prior.

problem Efficiently generating adversarial examples against black-box models.
method Prior-guided Bayesian Optimization (P-BO) with a function prior initialized from a surrogate model.
result Significantly reduces the number of queries needed for adversarial attacks.

Deep-PrAE improves rare-event simulation for black-box systems.

problem Evaluating rare safety-critical events in learning-based systems.
method Combines deep neural networks with IS to create statistically guaranteed estimations.
result Deep-PrAE provides accurate bounds on safety-critical event probabilities.

The paper tackles one-for-many counterfactual explanations using column generation.

problem Minimizing the number of explanations needed for a group of instances with sparsity constraints.
method Developed a novel column generation framework to efficiently search for explanations for any black-box classifier.
result The column generation framework outperforms existing methods in scalability, computational performance, and solution quality.

AutoZOOM reduces black-box attack query counts by 93% on MNIST, CIFAR-10, and ImageNet.

problem Efficiently attack black-box neural networks with minimal model queries.
method AutoZOOM uses an autoencoder and adaptive gradient estimation for query-efficient black-box attacks.
result Significant reduction in model queries (93%) without sacrificing attack success rate and visual quality.