Research map / Adversarial robustness and security
Black-box and transfer attacks: research map
383 accepted papers on Black-box and transfer attacks in Adversarial robustness and security, from ICML, NeurIPS, ICLR, CVPR and AAAI (2016–2026), grouped into 2 clusters and 7 approaches. The busiest year so far is 2025.
Within Adversarial robustness and security, its share held steady from 11.4% in 2023–24 to 11.8% in 2025–26 (89 → 116 papers at ICML, NeurIPS, CVPR and AAAI, the venues with data for all four years).
Explore Black-box and transfer attacks in the interactive map
Working on something in this topic? Describe your idea in scime atlas to see which approach it falls under, the closest papers by meaning and how crowded the spot has become.
Approaches and key papers
query · black box · box adversarial · 240 papers
Approaches in this cluster:
- Robustness benchmarks and defenses (89 papers)
Benchmark adversarial robustness and defend through architecture, denoising and loss design. - Query-efficient black-box attacks (78 papers)
Craft adversarial examples with limited queries via bandits, Bayesian optimization and priors. - Data-free substitute training (49 papers)
Attack black-box models by training substitutes without data or stealing models. - Decision-based boundary attacks (24 papers)
Attack models using only hard-label outputs by approximating decision boundaries.
Most cited and most cited since 2024:
- Ensemble Adversarial Training: Attacks and Defenses (ICLR 2018 · 2,314 citations)
- Defense Against Adversarial Attacks Using High-Level Representation Guided Denoiser (CVPR 2018 · 945 citations)
- DifAttack: Query-Efficient Black-Box Adversarial Attack via Disentangled Feature Space (AAAI 2024 · 22 citations)
- CosPGD: an efficient white-box adversarial attack for pixel-wise prediction tasks (ICML 2024 · 13 citations)
transferable · adversarial transferability · transferability adversarial · 143 papers
Approaches in this cluster:
- Transferable adversarial examples (86 papers)
Boost transfer of adversarial examples across models with gradient and input-diversity techniques. - Transfer attacks on face recognition (48 papers)
Improve transfer attacks with momentum and checkpoints, including against face recognition. - Transfer attacks on vision transformers (9 papers)
Exploit ViT components such as tokens and attention gradients for transferable attacks.
Most cited and most cited since 2024:
- Boosting Adversarial Attacks With Momentum (CVPR 2018 · 3,047 citations)
- Improving Transferability of Adversarial Examples With Input Diversity (CVPR 2019 · 1,273 citations)
- Boosting Adversarial Transferability by Block Shuffle and Rotation (CVPR 2024 · 88 citations)
- DiffAM: Diffusion-based Adversarial Makeup Transfer for Facial Privacy Protection (CVPR 2024 · 47 citations)
Related topics in Adversarial robustness and security
- Certified and empirical robustness (1,156)
- Backdoor and poisoning (320)
- Attacks on text and graphs (1,088)
