← Search

Xingquan Zuo

8 accepted papers

2026

Bias in Zeroth-Order Normal Estimation for Decision-Based Attacks

ICML 2026poster

Decision-based image attacks commonly rely on zeroth-order (ZO) Monte Carlo probing to estimate decision-boundary normals and iteratively refine adversarial perturbations to minimize the $\ell_2$ norm. We theoretically analyze and empirically demonstrate an intrinsic inefficiency arising from hetero…

Cited by 0SourceScholar
2026

SeRI: Gradient-Free Sensitive Region Identification in Decision-Based Black-Box Attacks

ICLR 2026poster

Deep neural networks (DNNs) are highly vulnerable to adversarial attacks, where small, carefully crafted perturbations are added to input images to cause misclassification. These perturbations are particularly effective when concentrated in sensitive regions of an image that strongly influence the m…

Cited by 0SourcecodeScholar
2025

ADBA: Approximation Decision Boundary Approach for Black-Box Adversarial Attacks

AAAI 2025technical

Many machine learning models are susceptible to adversarial attacks, with decision-based black-box attacks representing the most critical threat in real-world applications. These attacks are extremely stealthy, generating adversarial examples using hard labels obtained from the target machine learni…

2025

Advancing Community Detection with Graph Convolutional Neural Networks: Bridging Topological and Attributive Cohesion

IJCAI 2025

Community detection, a vital technology for real-world applications, uncovers cohesive node groups (communities) by leveraging both topological and attribute similarities in social networks. However, existing Graph Convolutional Networks (GCNs) trained to maximize modularity often converge to subopt

2025

IMPACT: Irregular Multi-Patch Adversarial Composition Based on Two‑Phase Optimization

NeurIPS 2025poster

Deep neural networks have become foundational in various applications but remain vulnerable to adversarial patch attacks. Crafting effective adversarial patches is inherently challenging due to the combinatorial complexity involved in jointly optimizing critical factors such as patch shape, location…

Cited by 0SourceScholar
2025

Query-Based and Unnoticeable Graph Injection Attack from Neighborhood Perspective

IJCAI 2025

The robustness of Graph Neural Networks (GNNs) has become an increasingly important topic due to their expanding range of applications. Various attack methods have been proposed to explore the vulnerabilities of GNNs, ranging from Graph Modification Attacks (GMA) to the more practical and flexible G

2025

RDI: An adversarial robustness evaluation metric for deep neural networks based on model statistical features

UAI 2025

Deep neural networks (DNNs) are highly susceptible to adversarial samples, raising concerns about their reliability in safety-critical tasks. Currently, methods of evaluating adversarial robustness are primarily categorized into attack-based and certified robustness evaluation approaches. The former

2025

TtBA: Two-third Bridge Approach for Decision-Based Adversarial Attack

ICML 2025poster

A key challenge in black-box adversarial attacks is the high query complexity in hard-label settings, where only the top-1 predicted label from the target deep model is accessible. In this paper, we propose a novel normal-vector-based method called Two-third Bridge Attack (TtBA). A innovative bridge…

Cited by 0SourcePDFScholar