OASIS: Optimizing Attacker Sequences for Hard-Label Black-Box Text Attacks

📅 2026-08-30
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
本文提出OURS方法,通过优化攻击序列来解决硬标签黑盒文本攻击问题,平衡攻击成功率与扰动,并在多个数据集上优于基线方法。
📝 Abstract
Different attack methods follow different search trajectories, they succeed on different subsets of samples, whereas existing hard-label black-box text attacks mainly focus on improving individual attackers or manually combining them. We present {\OURS}, a method for optimizing attacker sequences in hard-label black-box text attacks. {\OURS} first performs a one-time bi-objective attack chain search over candidate sequences to balance attack success rate and perturbation, and then reuses the selected fixed global chain during attack chain execution. Experiments across multiple datasets, victim models, and large language models show that {\OURS} consistently outperforms strong standalone baselines and simple manually constructed chains. These results suggest that attacker composition is not merely an implementation choice, but a practical optimization target for improving hard-label black-box text attacks.
Problem

Research questions and friction points this paper is trying to address.

hard-label black-box text attacks
attacker sequences
attack success rate
Innovation

Methods, ideas, or system contributions that make the work stand out.

Optimizing Attacker Sequences
Hard-Label Black-Box Text Attacks
Bi-Objective Attack Chain Search
🔎 Similar Papers
No similar papers found.
Qian Chen
Qian Chen
Massachusetts Institute of Technology, University of Pittsburgh
AI for DesignAdditive Manufacturing
S
Shiliang Xiao
School of Information Science and Technology, Guangdong University of Foreign Studies, China
Y
Yuzhi Liang
School of Information Science and Technology, Guangdong University of Foreign Studies, China