Stateful Detection of Black-Box Adversarial Attacks

Steven Chen, Nicholas Carlini, David Wagner · 2020

The problem of adversarial examples, evasion attacks on machine learning classifiers, has proven extremely difficult to solve. This is true even in the black-box threat model, as is the case in many practical settings. Here, the classifier is hosted as a remote service and the adversary does not have direct access to the model parameters.

Read the paper · More papers on PaperTik