Goto

Collaborating Authors

 random search






Meta-LearningtheSearchDistributionofBlack-Box RandomSearchBasedAdversarialAttacks

Neural Information Processing Systems

A very promising direction in the field of black-box adversarial attacks are randomized search schemes for crafting adversarial examples [1, 23, 24]. Combining random search with specific update proposal distributions allows to achieve state-of-the-art black-box efficiency for different threat models such as` and `2 [1], `1 [25], `0, adversarial patches, and adversarial frames [24].




OntheConvergenceofPrior-GuidedZeroth-Order OptimizationAlgorithms

Neural Information Processing Systems

Moreover,tofurther accelerate overgreedy descent methods, wepresent a new accelerated random search (ARS) algorithm that incorporates prior information, together with aconvergence analysis.


Appendix A Model details

Neural Information Processing Systems

The red lines in the bottom plot indicate linear fits and the red axis labels show the rank correlation coefficients ρ and p values. The matrix is orthogonal, thus avoiding a singular design. As scGen returns corrected input data, we performed PCA on the output data, which were used for further evaluation (cf. Appendix Section A.1). Here, we used the same number of principle components (PCs) as used for Embedded cells are colored by dataset. In Figure 9, we present the results of the simulation experiments discussed in the main text.